Vulnerability Intelligence Report
Android Pixel Information Disclosure Vulnerability
CVE-2023-21237
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
6.2
MEDIUM
Exploitability:2.6
Impact Score:3.6
EPSS Probability:0.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-200 ↗CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| android | 13.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Android (associated with Google Inc. or Open Handset Alliance) · Vendor · USA |
| Reserved | 2022-11-03T00:00:00 |
| Published | 2023-06-28T00:00:00 |
| Last Updated | 2025-10-21T23:05:44 |
Community Chatter & Buzz