CVE-2023-20955: High severity Google Android vulnerability
In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and uninstall applications for all users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-258653813
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-20955.
What is the severity of CVE-2023-20955?
The severity of CVE-2023-20955 is high (7.8).
Which versions of Google Android are affected by CVE-2023-20955?
Google Android versions 11.0, 12.0, 12.1, and 13.0 are affected by CVE-2023-20955.
What is the impact of CVE-2023-20955?
CVE-2023-20955 could lead to local escalation of privilege with no additional execution privileges needed.
How can I fix CVE-2023-20955?
To fix CVE-2023-20955, it is recommended to apply the security patch provided by Google and update to the latest version of Google Android.