CVE-2023-20957: High severity Google Android vulnerability
In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-258422561
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20957?
CVE-2023-20957 is a vulnerability in the onAttach function of SettingsPreferenceFragment.java in Android that allows for a possible bypass of Factory Reset Protection, leading to local escalation of privilege without additional execution privileges needed.
How does CVE-2023-20957 impact Android?
CVE-2023-20957 impacts Android versions 11.0, 12.0, and 12.1, potentially allowing a local escalation of privilege attack.
Is user interaction required for exploitation of CVE-2023-20957?
No, user interaction is not needed for exploitation of CVE-2023-20957.
What is the severity of CVE-2023-20957?
CVE-2023-20957 has a severity rating of 7.8, which is considered high.
How can I fix CVE-2023-20957 in Android?
To fix CVE-2023-20957, it is recommended to apply the security updates provided by Google for the affected Android versions (11.0, 12.0, and 12.1).