CVE-2023-35658 is a critical privilege escalation vulnerability affecting Google Android, stemming from a use-after-free error in the gatt_process_prep_write_rsp function. This flaw allows for remote code execution with high impact on confidentiality, integrity, and availability, requiring no user interaction or additional privileges, and can be exploited by an adjacent attacker. While it has been patched in Android's September updates and is not currently listed in CISA's KEV catalog, media reports indicate it was exploited as a zero-day. There are no public exploits or Metasploit modules available, but community discussion and media coverage suggest significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* | ||
12.1CPE matchmatch criteria | cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:* | ||
13.0CPE matchmatch criteria | cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.