CVE-2023-44126
Google Android 8.0 – 13.0
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:NSummary
CVE-2023-44126 is a low-severity Improper Verification of Intent by Broadcast Receiver (CWE-925) vulnerability in Google Android. Its CVSS base score is 3.6 (Low).
Operationally, exploitation aligns with the MITRE ATT&CK technique Inter-Process Communication (T1559); ranked at the 2th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-48485
Vulnerability Data
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as call states,…
more
durations, called numbers, contacts info, etc.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure development practices include explicit sender verification for broadcast receivers.
Verifying sender identity directly prevents unauthorized broadcast Intents.
Verifying identity assertions implements the missing authorization check for received Intents.
Enforcing authorization policy for the receiver mitigates the improper verification flaw.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect missing intent verification but does not prevent the weakness by itself.
Application security requirements can mandate intent verification for broadcast receivers.
Secure architecture principles include proper component authorization and input validation.
Secure coding practices directly address proper intent verification in broadcast receivers.