CVE-2023-21287: Critical severity android vulnerability
Published Aug 7, 2023
·Updated
In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
5 affected components
Google Android=11.0
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android
Remediation
Patch Available
Event History
Aug 7, 2023
CVE Published
via Android·12:00 AM
Aug 14, 2023
CVE Published
via MITRE·09:06 PM
Data Sourced
via MITRE·09:06 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-21287?
CVE-2023-21287 is classified as a critical vulnerability due to its potential for remote code execution without user interaction.
2
How do I fix CVE-2023-21287?
To mitigate CVE-2023-21287, users should update their affected Android devices to the latest security patch provided by Google.
3
Which versions of Android are affected by CVE-2023-21287?
CVE-2023-21287 impacts Android versions 11.0, 12.0, 12.1, and 13.0.
4
Is user interaction required for exploiting CVE-2023-21287?
No, exploitation of CVE-2023-21287 can occur without any user interaction.
5
What type of vulnerability is CVE-2023-21287?
CVE-2023-21287 is a type confusion vulnerability that can lead to remote code execution.