← Back to CVE List
Vulnerability Intelligence Report
Android Framework Privilege Escalation Vulnerability

CVE-2023-35674

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.1
Impact Score:6.1
EPSS Probability:2.20%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-269 ↗CWE-269 Improper Privilege Management

Affected Products & Versions

Vendor Product Affected Versions
Google Android 13 (affected), 12L (affected), 12 (affected), 11 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
2.203%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAndroid (associated with Google Inc. or Open Handset Alliance) · Vendor · USA
Reserved2023-06-15T02:50:29
Published2023-09-11T20:09:53
Last Updated2025-10-21T23:05:38

LINK COPIED TO CLIPBOARD