CVE-2023-0460 (CNNVD-202303-084)
中文标题:
Alphabet YouTube Embedded 安全漏洞
英文标题:
Remote code execution in YouTube Android Player API SDK
漏洞描述
中文描述:
Alphabet YouTube Embedded是美国Alphabet公司的一个视频分享应用程序。 Alphabet YouTube Embedded 1.2 SDK版本存在安全漏洞,该漏洞源于SDK可以加载恶意应用程序的ClassLoader。
英文描述:
The YouTube Embedded 1.2 SDK binds to a service within the YouTube Main App. After binding, a remote context is created with the flags Context.CONTEXT_INCLUDE_CODE | Context.CONTEXT_IGNORE_SECURITY. This allows the client app to remotely load code from YouTube Main App by retrieving the Main App’s ClassLoader. A potential vulnerability in the binding logic used by the client SDK where the SDK ends up calling bindService() on a malicious app rather than YT Main App. This creates a vulnerability where the SDK can load the malicious app’s ClassLoader instead, allowing the malicious app to load arbitrary code into the calling app whenever the embedded SDK is invoked. In order to trigger this vulnerability, an attacker must masquerade the Youtube app and install it on a device, have a second app that uses the Embedded player and typically distribute both to the victim outside of the Play Store.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| YouTube Android Player API SDK | - | ≤ 1.2.2 | - |
cpe:2.3:a:google:youtube_android_player_api_sdk:*:*:*:*:*:*:*:*
|
|
| youtube_android_player_api | * | - | - |
cpe:2.3:a:google:youtube_android_player_api:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2023-0460 |
2025-11-11 15:21:45 | 2025-11-11 07:37:59 |
| NVD | nvd_CVE-2023-0460 |
2025-11-11 14:58:57 | 2025-11-11 07:46:09 |
| CNNVD | cnnvd_CNNVD-202303-084 |
2025-11-11 15:11:08 | 2025-11-11 07:57:49 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202303-084
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']