CVE-2023-20917: High severity Google Android vulnerability
In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242605257
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20917?
CVE-2023-20917 is a vulnerability in the Android operating system that allows for local escalation of privilege through a logic error in the code.
What is the severity of CVE-2023-20917?
CVE-2023-20917 has a severity rating of 7.8, which is considered high.
Which versions of Android are affected by CVE-2023-20917?
Android versions 11.0, 12.0, 12.1, and 13.0 are affected by CVE-2023-20917.
Is user interaction required for exploitation of CVE-2023-20917?
No, user interaction is not needed for exploitation of CVE-2023-20917.
How can I fix CVE-2023-20917?
To fix CVE-2023-20917, install the latest security update provided by Google for your Android version.