CVE CVE

CVE-2023-21237

CISA Known Exploited Vulnerability (KEV)

Android Pixel Information Disclosure Vulnerability

March 5, 2024

March 26, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912

Weakness Enumeration

CWE-ID CWE Name

CWE-200
Exposure of Sensitive Information to an Unauthorized Actor

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
5.5
Severity:

MEDIUM

Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v2

Not defined