First published: Mon Aug 07 2023(Updated: )
In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20965 is considered a high severity vulnerability that could lead to remote escalation of privilege.
To mitigate CVE-2023-20965, ensure that your Android device is updated to the latest security patch provided by Google.
CVE-2023-20965 affects Android version 13.0 and potentially other versions as updates are released.
Yes, CVE-2023-20965 can be exploited remotely without any user interaction required.
Exploitation of CVE-2023-20965 could result in unauthorized access to credentials, leading to privilege escalation.