Foreground Service Notification Bypass Vulnerability

Foreground Service Notification Bypass Vulnerability

CVE-2023-40120 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Learn more about our User Device Pen Test.