nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-21237 CVE-2023-21237
MEDIUMCISA KEV
Android Pixel Information Disclosure Vulnerability
Record summary
CVE-2023-21237 has a selected CVSS score of 6.2 (medium). CISA lists CVE-2023-21237 in KEV.
Description
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Mar 5, 2024 · CISA
- VulnCheck KEV
- Listed · Jun 13, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 5, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
| CISA | Version data not supplied | ||
androidBrowse google / androidDefault status: unknown | CVE List | 13.0 | affected |
Android | CVE List | Android-13 | affected |
References
3source.android.com
https://source.android.com/security/bulletin/pixel/2023-06-01 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-21237