CVE-2023-44121
LG ThinQ Service - Intent redirection with system privilege/LaunchAnyWhere
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending a broadcast with the action "com.lge.lms.things.notification.ACTION". Additionally, this vulnerability is very dangerous because LG ThinQ Service is a system app (having android:sharedUserId="android.uid.system" setting). Intent redirection in this app leads to accessing arbitrary not exported activities of absolutely all apps.
La vulnerabilidad es una redirección de intención en LG ThinQ Service ("com.lge.lms2") en el archivo "com/lge/lms/things/ui/notification/NotificationManager.java". Esta vulnerabilidad podría ser aprovechada por una aplicación de terceros instalada en un dispositivo LG enviando una transmisión con la acción "com.lge.lms.things.notification.ACTION". Además, esta vulnerabilidad es muy peligrosa porque LG ThinQ Service es una aplicación del sistema (que tiene la configuración android:sharedUserId="android.uid.system"). La redirección de intenciones en esta aplicación conduce a acceder a actividades arbitrarias no exportadas de absolutamente todas las aplicaciones.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-09-26 CVE Reserved
- 2023-09-27 CVE Published
- 2023-10-03 EPSS Updated
- 2024-09-23 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-926: Improper Export of Android Application Components
CAPEC
- CAPEC-122: Privilege Abuse
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://lgsecurity.lge.com/bulletins/mobile#updateDetails | 2023-10-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | >= 9.0 <= 13.0 Search vendor "Google" for product "Android" and version " >= 9.0 <= 13.0" | - |
Affected
| in | Lg Search vendor "Lg" | V60 Thin Q 5g Search vendor "Lg" for product "V60 Thin Q 5g" | - | - |
Safe
|