CVE-2023-21237
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information.
CISA KEV
- Vendor
- Android
- Product
- Pixel
- Due date
- 2024-03-26
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://source.android.com/docs/security/bulletin/pixel/2023-06-01; https://nvd.nist.gov/vuln/detail/CVE-2023-21237
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.