CVE-2023-20947: High severity Google Android vulnerability
In getGroupState of GrantPermissionsViewModel.kt, there is a possible way to keep a one-time permission granted due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237405974
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-20947.
What is the severity of CVE-2023-20947?
The severity of CVE-2023-20947 is high with a CVSS score of 7.8.
How does CVE-2023-20947 impact Google Android?
CVE-2023-20947 could lead to local escalation of privilege in Google Android.
Is user interaction required for exploitation of CVE-2023-20947?
No, user interaction is not needed for exploitation of CVE-2023-20947.
How can I fix CVE-2023-20947?
To fix CVE-2023-20947, you should apply the necessary patches and updates provided by Google for the affected versions of Android.