Junglewise Threat Intelligence

CVE-2023-35674: Android Framework Privilege Escalation Vulnerability

CVE-2023-35674 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-09-13

Technologies: Android Framework, Google Android. Vendors: Android, Google.

Executive brief

A logic error in the onCreate method of WindowState.java in the Android Framework allows for the unauthorized launching of background activities. This vulnerability enables a local attacker to escalate privileges without requiring additional execution permissions or user interaction.

Affected products

  • Google Android 11.0, 12.0, 12.1, 13.0

Timeline

  • 2023-09-01: patched: Vendor advisory and patch released.
  • 2023-09-11: disclosed: NVD Published Date.
  • 2023-09-13: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog.
  • 2023-09-13: exploited: Reported as exploited in the wild.

Related threats