google android CVE-2023-21237 is a vulnerability in Google Android
Published on June 28, 2023

In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912

Vendor Advisory NVD

Known Exploited Vulnerability

This Android Pixel Information Disclosure Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information.

The following remediation steps are recommended / required by March 26, 2024: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Vulnerability Analysis

CVE-2023-21237 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. It has an exploitability score of 1.8 out of four. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.


Products Associated with CVE-2023-21237

You can be notified by stack.watch whenever vulnerabilities like CVE-2023-21237 are published in these products:

 

What versions of Android are vulnerable to CVE-2023-21237?