← Back to browse · API

CVE-2023-35674

Severity
HIGH
CVSS
8.8
EPSS
0.02203
Risk score
60.97
CISA KEV
Yes
PoC
No
Published
2023-09-11
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2023-39674, GHSA-48CJ-HMGX-8F7H
Products
Android:Framework, Google:Android 11, Google:Android 12, Google:Android 12L, Google:Android 13
Sources
cisa.gov CVE-2023-35674
euvd EUVD-2023-39674

Description

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References