CVE-2023-20944
In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-244154558
- Affected products
- Android
- Google Android
- = 10.0, 11.0, 12.0, 12.1, 13.0
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.2% (9th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2023-02-28
CVE-2023-20944 at NVD
1 known exploit for CVE-2023-20944
Proof-of-concept code and exploit modules indexed by Sploitus