VYPR
Unrated severityNVD Advisory· Published Aug 10, 2023· Updated Oct 4, 2024

CVE-2023-30700

CVE-2023-30700

Description

PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

PendingIntent hijacking in SemWifiApTimeOutImpl allows local attackers to access ContentProvider without proper permission.

Vulnerability

A PendingIntent hijacking vulnerability exists in the SemWifiApTimeOutImpl class of the Android framework on Samsung devices. Affected versions are those prior to the SMR Aug-2023 Release 1 security update. The bug allows a malicious app to intercept and modify a PendingIntent, leading to unauthorized access to a ContentProvider that should require specific permissions.

Exploitation

An attacker with local access to the device can exploit this by crafting a malicious PendingIntent that intercepts the intended one. No additional authentication or privileges are needed beyond installing an app on the device. The attacker then triggers the hijacked intent, which performs a permission check against the attacker's app rather than the original sender, allowing access to the ContentProvider.

Impact

Successful exploitation enables the attacker to read or modify data stored in the vulnerable ContentProvider, which may include sensitive device or user information, such as Wi-Fi configuration details or other system data. This results in a confidentiality and integrity breach, with the attacker gaining unauthorized data access without the intended permission enforcement.

Mitigation

Samsung released a fix as part of the SMR Aug-2023 Release 1 security update [1]. Users should ensure their device is updated to the latest security patch level. No workaround exists other than applying the update.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.