ZeroHour

CVE-2023-21237

KEVmass

Information Disclosure via Hidden Foreground Service Notifications on Android 13 Pixels

CISA: Android Pixel Information Disclosure Vulnerability

CVSS 3.1
5.5 medium
EPSS
<1%p18
Published
()
KEV added
AI analysis

CVE-2023-21237 is an information disclosure flaw (CWE-200) in the applyRemoteView function of NotificationContentInflater.java on Android 13, where misleading or insufficient UI can cause a foreground service notification to be hidden from the user. A locally installed app with only low privileges can trigger the condition without any user interaction, causing the system not to visibly display the app's foreground service notification. An attacker gains a covert execution context: the user receives no indication that an app or service is running, which Google classifies as local information disclosure because the user is deprived of awareness of activity on their device. Affected users are those with Google Pixel devices running Android 13, per CISA's advisory. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-03-05, confirming in-the-wild exploitation, though EPSS currently estimates only a 0.3% probability of exploitation in the next 30 days and no public PoC is known.

What to do: Apply Google's latest Pixel/Android monthly security update to all Android 13 Pixel devices, prioritizing fleet patching per the CISA KEV required action, and verify devices report a security patch level that includes this fix. As a detection aid, review installed apps that run foreground services whose notifications are not visible, since hiding the foreground service notification is the core abuse of this flaw. If patching is not possible, follow vendor mitigations per CISA guidance or discontinue use of affected devices.

Affected
Google Android (Pixel devices)
Estimated exposure
massmillions of Pixel devices running Android 13 (a subset of Google's estimated tens-of-millions cumulative Pixel install base) — Google does not publish Pixel unit counts, but cumulative Pixel sales are widely estimated in the tens of millions and Android 13 was the stock/current OS across Pixel 4-and-newer devices, so the affected population is plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912

CISA Known Exploited Vulnerability
Affected
Android Pixel
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
google
Products
android
Weakness
CWE-200
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news