Junglewise Threat Intelligence

CVE-2023-20963: Android Framework Privilege Escalation Vulnerability

CVE-2023-20963 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-04-13

Technologies: Android Framework, Google Android. Vendors: Android, Google.

Executive brief

A parcel mismatch vulnerability in the WorkSource component of the Android Framework allows for local escalation of privilege. Exploitation can occur after updating an app to a higher Target SDK and requires no additional execution privileges or user interaction.

Affected products

  • Google Android 11, 12, 12L, 13

Timeline

  • 2023-03-01: patched: Security bulletin published by Android vendor.
  • 2023-03-24: disclosed: NVD Published Date.
  • 2023-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats