CVE-2023-21237
Last modified
CVE-2023-21237 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. CISA has confirmed active exploitation in the wild. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 13.0 |
References
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-21237Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-21237?
How severe is CVE-2023-21237?
How do I fix CVE-2023-21237?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-21231In getIntentForButton of ButtonManager.java, there is a poss…7.8
- CVE-2023-21232In multiple locations, there is a possible way to retrieve s…3.3
- CVE-2023-21233In multiple locations of avrc, there is a possible leak of h…7.5
- CVE-2023-21234In launchConfirmationActivity of ChooseLockSettingsHelper.ja…5.5
- CVE-2023-21235In onCreate of LockSettingsActivity.java, there is a possibl…7.8
- CVE-2023-21236In aoc_service_set_read_blocked of aoc.c, there is a possibl…6.7
- CVE-2023-21238In visitUris of RemoteViews.java, there is a possible leak o…5.5
- CVE-2023-21239In visitUris of Notification.java, there is a possible way t…5.5
- CVE-2023-2124An out-of-bounds memory access flaw was found in the Linux k…7.8
- CVE-2023-21240In Policy of Policy.java, there is a possible boot loop due …5.5
- CVE-2023-21241In rw_i93_send_to_upper of rw_i93.cc, there is a possible ou…7.8
- CVE-2023-21242In isServerCertChainValid of InsecureEapNetworkHandler.java,…9.8
Are you affected by CVE-2023-21237?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
