CISA Known Exploited Vulnerability

CVE-2023-20963

Android · Framework

Android Framework Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-295
Ransomware Unknown

CISA description

Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed.

Required action

Apply updates per vendor instructions.