First published: Mon Mar 06 2023(Updated: )
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519
Credit: security@android.com security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =11.0 | |
Google Android | =12.0 | |
Google Android | =12.1 | |
Google Android | =13.0 | |
Android Framework | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20963 is a privilege escalation vulnerability in the Android Framework.
CVE-2023-20963 allows for privilege escalation in Android Framework when updating an app to a higher Target SDK with no additional execution privileges needed.
Android Framework users are affected by CVE-2023-20963.
An attacker can exploit CVE-2023-20963 to escalate privileges in Android Framework.
To protect yourself from CVE-2023-20963, ensure you apply the latest security updates and patches provided by Android Framework.