CVE-2023-21237

CVE Published 2023-06-28
Related CWE(s) CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Related Vendor(s) google
Related Product(s) android
Exploitation Reported (CISA KEV) 2024-03-05
CVSS 3 Base Score 6.2 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References