HIGH

CVE-2023-20963

Google Android 2023-03-24 CVSS v3.1
CVSS
7.8
KEV

Description

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519

Summary dbcve.org

This is a local privilege escalation vulnerability in Android's WorkSource component caused by a parcel mismatch during Inter-Process Communication (IPC). A parcel mismatch occurs when data serialization/deserialization between processes uses incompatible data structures, potentially allowing a local attacker to escalate privileges without requiring additional execution capabilities or user interaction.

Mitigation

Apply the Android security patch for the affected versions (Android 11, 12, 12L, 13). Organizations with custom Android implementations should obtain the upstream fix from Google's Android Security Bulletins and ensure timely deployment of monthly security updates.

Patch Commit

Weakness (CWE)

CWE-295 Improper Certificate Validation

EPSS Score

1.47%
Probability of exploitation in next 30 days
72.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE