← Back to browse · API

CVE-2023-48418

Severity
CRITICAL
CVSS
10.0
EPSS
0.0022
Risk score
40.08
CISA KEV
No
PoC
No
Published
2024-01-02
Modified
2025-06-03
First seen
2026-08-07
Aliases
EUVD-2023-52469, GHSA-WQMR-CP8M-946M
Products
Google:Pixel Watch 11
Sources
euvd EUVD-2023-52469

Description

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default     value. This could lead to local escalation of privilege with no additional     execution privileges needed. User interaction is not needed for     exploitation

References