← Back to browse · API

CVE-2023-20963

Severity
HIGH
CVSS
7.8
EPSS
0.01465
Risk score
56.71
CISA KEV
Yes
PoC
No
Published
2023-04-13
Modified
2023-04-13
First seen
2026-08-07
Aliases
EUVD-2023-25131, GHSA-XM9F-FPH8-8369
Products
Android:Framework, Google:Android Android-11 Android-12 Android-12L Android-13
Sources
euvd EUVD-2023-25131
cisa.gov CVE-2023-20963

Description

Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed.

References