peter bassill · operator
$ cve CVE-2023-21237 JSON

CVE-2023-21237 KEV

5.5
MEDIUM · CVSS 3.1 · EPSS 0.3% (pctl 17)

Patch first

On CISA KEV — known exploited in the wild, due 2024-03-26.

Description

In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912

Scoring

CVSS5.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS0.27% — more likely to be exploited than 17% of all CVEs
WeaknessCWE-200
On CISA KEVyes — remediate by 2024-03-26
Public exploitnone known
Published2023-06-28
Last modified2026-06-17

CISA KEV

NameAndroid Pixel Information Disclosure Vulnerability
Added2024-03-05
Due2024-03-26
Vendor / productAndroid / Pixel
Ransomware usenone reported

Affected (1)

VendorProduct
googleandroid

References

→ the Explorer  ·  watch your stack  ·  NVD