Junglewise Threat Intelligence

CVE-2023-21237: Android Pixel Information Disclosure Vulnerability

CVE-2023-21237 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2024-03-05

Technologies: Android Pixel, Google Android. Vendors: Android, Google.

Executive brief

A vulnerability in the Framework component of Android 13 (specifically in NotificationContentInflater.java) allows for the concealment of foreground service notifications due to misleading or insufficient UI. This flaw can be exploited by a local attacker to disclose sensitive information without requiring additional execution privileges or user interaction.

Affected products

  • Google Android 13

Timeline

  • 2023-06-01: advisory: Vendor advisory published by Android/Google
  • 2023-06-28: disclosed: NVD Published Date
  • 2024-03-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-03-05: exploited: Reported as exploited in the wild per CISA KEV entry

Related threats