{ "id": "CVE-2023-35671", "sourceIdentifier": "security@android.com", "published": "2023-09-11T21:15:42.080", "lastModified": "2023-09-12T11:52:10.097", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation." } ], "metrics": {}, "references": [ { "url": "https://android.googlesource.com/platform/packages/apps/Nfc/+/745632835f3d97513a9c2a96e56e1dc06c4e4176", "source": "security@android.com" }, { "url": "https://source.android.com/security/bulletin/2023-09-01", "source": "security@android.com" } ] }