Back to Labs
Security Advisory

CVE-2023-21349

About

In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness (CWE):CWE-203

Rainforest analyst review

On Android, a side channel in Package Manager lets an app determine whether another specific app is installed, without holding the query permission that is supposed to gate exactly that information. The impact is a small, local information leak: it reveals presence of other apps to code already running on the device, with no execution privileges gained and no user interaction involved.

This is fingerprinting-grade information, not a compromise. It can help a malicious or overly curious app profile the device, which apps to target or how to tailor a lure, but it discloses nothing beyond installation state and grants no additional access. There is no remote vector and no mass-exploitation angle; realistically it is a building block a bad app might use, weighed against everything else that already-installed malicious code could do.

We rank this near the floor, consistent with its 3.3. It rides the normal Android security-patch level with no special handling, and the only meaningful control on our side is the mobile-management baseline, keeping devices current and vetting installed apps, rather than anything that treats this specific side channel as noteworthy.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2023-21349?

In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

How severe is CVE-2023-21349?

CVE-2023-21349 carries a CVSS 3.1 base score of 3.3, rated low. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 34 out of 100, in the moderate band.

How is CVE-2023-21349 exploited?

According to the CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N): attack vector Local, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality Low, integrity None and availability None.

Which products are affected by CVE-2023-21349?

Public advisories list the following as affected: android. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-21349?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email