CVE-2023-20963

CVE Published 2023-03-24
Related CWE(s) CWE-295: Improper Certificate Validation
Related Vendor(s) google
Related Product(s) android
Exploitation Reported (CISA KEV) 2023-04-13
CVSS 3 Base Score 7.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References