CVE-2023-20964: High severity Google Android vulnerability
In multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This could lead to local denial of service or escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-238177121
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20964?
The severity of CVE-2023-20964 is high with a severity value of 7.8.
How does CVE-2023-20964 affect Android?
CVE-2023-20964 affects Android versions 12.0, 12.1, and 13.0.
What is the impact of CVE-2023-20964?
CVE-2023-20964 could lead to local denial of service or escalation of privilege with no additional execution privileges needed.
Is user interaction required for exploitation of CVE-2023-20964?
No, user interaction is not needed for exploitation of CVE-2023-20964.
How can I fix CVE-2023-20964?
To fix CVE-2023-20964, it is recommended to apply the necessary security patches provided by Google for the affected Android versions.