peter bassill · operator
$ cve CVE-2023-35674 JSON

CVE-2023-35674 KEV

7.8
HIGH · CVSS 3.1 · EPSS 2.6% (pctl 85)

Patch first

On CISA KEV — known exploited in the wild, due 2023-10-04.

Description

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS2.62% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-269
On CISA KEVyes — remediate by 2023-10-04
Public exploitnone known
Published2023-09-11
Last modified2026-06-17

CISA KEV

NameAndroid Framework Privilege Escalation Vulnerability
Added2023-09-13
Due2023-10-04
Vendor / productAndroid / Framework
Ransomware usenone reported

Affected (1)

VendorProduct
googleandroid

References

→ the Explorer  ·  watch your stack  ·  NVD