Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-35674 PoC — Google Android 安全漏洞

Source
Associated Vulnerability
Title: Google Android 安全漏洞 (CVE-2023-35674)
Description:In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Description
ช่องโหว่ CVE-2023-35674 *สถานะ: ยังไม่เสร็จ*
Readme
## อธิบาย

**CVE-2023-35674 คือช่องโหว่ความปลอดภัยระดับสูงประเภท zero-day ที่อยู่ใน Android Framework ช่องโหว่นี้อนุญาตให้ผู้โจมตีสามารถยกระดับสิทธิ์ของตนเองได้โดยไม่ต้องมีปฏิสัมพันธ์กับผู้ใช้หรือสิทธิ์การเรียกใช้เพิ่มเติม**

**ช่องโหว่นี้เกิดขึ้นในวิธีการทำงานของ Android Framework ในการจัดการกับไฟล์แคชของแพ็กเกจแอปพลิเคชัน ผู้โจมตีสามารถใช้ช่องโหว่นี้เพื่อแก้ไขไฟล์แคชของแอปพลิเคชันเพื่อให้สามารถเรียกใช้โค้ดที่เป็นอันตรายได้**

**ช่องโหว่นี้ได้รับการรายงานต่อ Google เมื่อวันที่ 22 สิงหาคม 2023 และ Google ได้ออกการอัปเดตเพื่อแก้ไขช่องโหว่นี้เมื่อวันที่ 2 สิงหาคม 2023**

**ผู้โจมตีสามารถใช้ช่องโหว่นี้เพื่อติดตั้งมัลแวร์บนอุปกรณ์ Android, ขโมยข้อมูลส่วนบุคคล หรือควบคุมอุปกรณ์**

**รายละเอียดเพิ่มเติมเกี่ยวกับช่องโหว่ CVE-2023-35674:**

* **ประเภท: zero-day**
* **ระดับความรุนแรง: สูง**
* **ผลกระทบ: ผู้โจมตีสามารถยกระดับสิทธิ์ของตนเองได้**
* **ตำแหน่ง: Android Framework**
* **วิธีแก้: แก้ไขไฟล์แคชของแอปพลิเคชัน**
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →