SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-21237

Android Pixel Information Disclosure Vulnerability

KEVMEDIUM 5.5EPSS 0.26%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 26 March 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.26% probability · 18th percentile
CISA KEV
Listed 5 March 2024 · due 26 March 2024
Weakness
CWE-200
Affected
google/android
Source
security@android.com

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://source.android.com/docs/security/bulletin/pixel/2023-06-01; https://nvd.nist.gov/vuln/detail/CVE-2023-21237

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.