CVE-2023-20906: High severity Google Android vulnerability
In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently grant a permission after a Target SDK update due to a permissions bypass. This could lead to local escalation of privilege after updating an app to a higher Target SDK with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-221040577
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20906?
CVE-2023-20906 is considered a moderate severity vulnerability that allows for potential local escalation of privilege.
How do I fix CVE-2023-20906?
To mitigate CVE-2023-20906, users should update their Android devices to the latest available security patch.
What versions of Android are affected by CVE-2023-20906?
CVE-2023-20906 affects Android versions 11.0, 12.0, 12.1, and 13.0.
What type of vulnerability is CVE-2023-20906?
CVE-2023-20906 is a permissions bypass vulnerability in the PermissionManagerService.
Can CVE-2023-20906 be exploited remotely?
No, CVE-2023-20906 requires local access to exploit the permissions bypass.