CVE-2023-48418

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
02/01/2024
Last modified:
13/02/2025

Description

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a<br />     possible way to access adb before SUW completion due to an insecure default<br />     value. This could lead to local escalation of privilege with no additional<br />     execution privileges needed. User interaction is not needed for<br />     exploitation

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:google:pixel_watch_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:google:pixel_watch:11:*:*:*:*:*:*:*