CVE-2023-44126
EUVD-2023-4848527.09.2023, 15:19
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as call states, durations, called numbers, contacts info, etc.EnginsightAffected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| android | 8.0 ≤ 𝑥 ≤ 13.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration