
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-45774 is a security vulnerability discovered in Android's ShortcutService.java, specifically in the fixUpIncomingShortcutInfo function. The vulnerability was disclosed in December 2023 and affects Android versions 11 through 14. This vulnerability allows unauthorized access to view another user's image due to a confused deputy issue (Android Bulletin, NVD).
The vulnerability exists in the fixUpIncomingShortcutInfo function of ShortcutService.java. It has been assigned a CVSS v3.1 base score of 7.8 (HIGH), with the following vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The vulnerability requires local access but has low attack complexity and requires no user interaction for exploitation (NVD).
The vulnerability can lead to local escalation of privilege with no additional execution privileges needed. It allows an attacker to view another user's image, potentially compromising user privacy and security (NVD).
Google has addressed this vulnerability with a patch that validates URI-based shortcut icons at creation time. The fix was implemented in the Android codebase through a commit by Pinyao Ting (Android Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."