CVE-2023-20963
Description
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519
Summary dbcve.org
This is a local privilege escalation vulnerability in Android's WorkSource component caused by a parcel mismatch during Inter-Process Communication (IPC). A parcel mismatch occurs when data serialization/deserialization between processes uses incompatible data structures, potentially allowing a local attacker to escalate privileges without requiring additional execution capabilities or user interaction.
Mitigation
Apply the Android security patch for the affected versions (Android 11, 12, 12L, 13). Organizations with custom Android implementations should obtain the upstream fix from Google's Android Security Bulletins and ensure timely deployment of monthly security updates.