CVE-2023-29767
Description
An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the database files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Local attacker can cause persistent denial of service in CrossX v.1.15.3 for Android by injecting excessive data into exposed content provider, leading to OOM crash.
Vulnerability
The CrossX application (com.startapps.crossx) version 1.15.3 for Android exposes a content provider at content://com.startapps.crossx.contentprovider/tb_user that allows any application to insert data into the app's database [1]. The app loads the entire database into memory upon startup. By injecting an excessive amount of data (e.g., large strings into the email column), the database grows large enough to cause an out-of-memory (OOM) error, crashing the app persistently [1].
Exploitation
A local attacker needs only an app on the same device that can call ContentResolver.insert() on the exposed content provider URI [1]. No additional permissions are required because the provider does not enforce access restrictions. The provided proof-of-concept demonstrates a loop that repeatedly inserts random 10 KB strings into the tb_user table [1]. The attack requires no user interaction with CrossX; once the injection begins, the data persists in the database, ensuring the crash recurs on every attempt to launch CrossX [1].
Impact
Successful exploitation results in a persistent denial of service: the CrossX app crashes immediately upon startup due to an OOM error [1]. The user cannot recover by simply restarting the app; the only remedies are clearing the app's data or uninstalling it, both of which delete the injected database files. The impact is limited to loss of availability of the CrossX application [1].
Mitigation
As of the publication date (2023-06-09), no patch or updated version has been released by the vendor (CROSSX SOLUÇÕES MOBILE LTDA) [1]. Users can uninstall the app or restrict access to the content provider using third-party tools or a custom Android ROM with permission management. The vulnerability is not known to be listed on CISA's Known Exploited Vulnerabilities catalog [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- CrossX/CrossXdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.