CVE-2023-35674 Details
Description
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
A logic error in the Android Framework's WindowState component allows for the unintentional launch of a background activity. This vulnerability could lead to local privilege escalation, requiring no additional execution privileges or user interaction for exploitation. It affects Android versions 11, 12, 12L, and 13.
Users can update their devices to the September 2023 security patch level to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-35674 | CISA-ADP | Third Party AdvisoryUS Government Resource |
| https://android.googlesource.com/platform/frameworks/base/+/7428962d3b064ce1122809d87af65099d1129c9e | CVE | Patch |
| https://source.android.com/security/bulletin/2023-09-01 | CVE | PatchVendor Advisory |
| https://android.googlesource.com/platform/frameworks/base/+/7428962d3b064ce1122809d87af65099d1129c9e | [email protected] | Patch |
| https://source.android.com/security/bulletin/2023-09-01 | [email protected] | PatchVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Android Framework Privilege Escalation Vulnerability | Sep 13, 2023 | Oct 4, 2023 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-269 | Improper Privilege Management | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google android | 11.0 12.0 12.1 13.0 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Oct 23, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Jul 30, 2025 | Modified Analysis | [email protected] |
| Jul 30, 2025 | CVE Modified | CISA-ADP |
| Dec 20, 2024 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Sep 30, 2024 | Modified Analysis | [email protected] |
| Sep 26, 2024 | CVE Modified | CISA-ADP |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 14, 2023 | Initial Analysis | [email protected] |