CVE-2023-20963
KEVmassLocal Privilege Escalation in Android Framework (WorkSource Parcel Mismatch)
CISA: Android Framework Privilege Escalation Vulnerability
CVE-2023-20963 is a local privilege escalation vulnerability in the Android Framework's WorkSource component, caused by a parcel mismatch (improperly handled parcel data) on devices running Android 11, 12, 12L, and 13. A malicious or compromised app already on the device can trigger the mismatch with no additional execution privileges and no user interaction, making it a low-friction vector once an attacker has any local foothold. Successful exploitation escalates privileges beyond the normal app sandbox - the CVSS 7.8 vector scores high confidentiality, integrity, and availability impact while requiring only low local privileges, indicating substantial system-level access. Any Android device on versions 11 through 13 that has not received the vendor's security patch is potentially affected, which spans a large share of the global smartphone and tablet fleet. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-13 (EPSS currently estimates a 1.5% probability of exploitation in the next 30 days), and related news coverage - including Google's suspension of the Chinese e-commerce app Pinduoduo over malware - links the exploited bug to a broader malware campaign.
What to do: Apply the latest Android security updates from your device vendor or OEM as soon as they are issued, prioritizing all devices on Android 11, 12, 12L, or 13 - this is the required action CISA lists for this KEV entry. Until patched, avoid installing apps from untrusted sources, since exploitation requires the attacker to already run code locally on the device. Administrators should inventory Android 11-13 endpoints via MDM/EMM and track the fix by Android bug ID A-220302519.
| google android | Android 11, Android 12, Android 12L, and Android 13 (Android Framework component; Android bug ID A-220302519) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519
- Affected
- Android Framework
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Products
- android
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H