CVE-2023-35674
Android Framework Privilege Escalation Vulnerability
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
HIGH · CVSS 7.8
⚠ CISA KEV
EPSS 0.00087
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0