#VU77992 Input validation error in Android Automotive OS (AAOS) - CVE-2023-21260
Published: July 5, 2023
Android Automotive OS (AAOS)
Description
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to insufficient validation of user-supplied input. A malicious application can embed a service label that overflow the original user prompt and possibly contain mis-leading information as a system message for user confirmation.