Skip to main content

Use of Implicit Intent for Sensitive Communication

CVE-2023-44127

Severity Low
Score 3.6/10

Summary

he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as contact details and phone numbers.

  • LOW
  • LOCAL
  • NONE
  • CHANGED
  • REQUIRED
  • NONE
  • LOW
  • NONE

CWE-927 - Use of Implicit Intent for Sensitive Communication

The Android application uses an implicit intent for transmitting sensitive data to other applications.

References

Advisory Timeline

  • Published