Skip to main content

Improper Export of Android Application Components

CVE-2023-21486

Severity Medium
Score 5.3/10

Summary

Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.

  • LOW
  • PHYSICAL
  • NONE
  • CHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-926 - Improper Export of Android Application Components

The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.

References

Advisory Timeline

  • Published