← Back to browse · API

CVE-2023-21237

Severity
MEDIUM
CVSS
6.2
EPSS
0.00264
Risk score
49.89
CISA KEV
Yes
PoC
No
Published
2023-06-28
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2023-25405, GHSA-QHM9-GG74-G6M6
Products
Android:Pixel, Google:Android Android-13
Sources
euvd EUVD-2023-25405
cisa.gov CVE-2023-21237

Description

In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912

References