CVE-2023-48418

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a
  possible way to access adb before SUW completion due to an insecure default
  value. This could lead to local escalation of privilege with no additional
  execution privileges needed. User interaction is not needed for
  exploitation
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Google_DevicesCNA
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---