CVE-2023-21237
KEVmassInformation Disclosure via Hidden Foreground Service Notifications on Android 13 Pixels
CISA: Android Pixel Information Disclosure Vulnerability
CVE-2023-21237 is an information disclosure flaw (CWE-200) in the applyRemoteView function of NotificationContentInflater.java on Android 13, where misleading or insufficient UI can cause a foreground service notification to be hidden from the user. A locally installed app with only low privileges can trigger the condition without any user interaction, causing the system not to visibly display the app's foreground service notification. An attacker gains a covert execution context: the user receives no indication that an app or service is running, which Google classifies as local information disclosure because the user is deprived of awareness of activity on their device. Affected users are those with Google Pixel devices running Android 13, per CISA's advisory. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-03-05, confirming in-the-wild exploitation, though EPSS currently estimates only a 0.3% probability of exploitation in the next 30 days and no public PoC is known.
What to do: Apply Google's latest Pixel/Android monthly security update to all Android 13 Pixel devices, prioritizing fleet patching per the CISA KEV required action, and verify devices report a security patch level that includes this fix. As a detection aid, review installed apps that run foreground services whose notifications are not visible, since hiding the foreground service notification is the core abuse of this flaw. If patching is not possible, follow vendor mitigations per CISA guidance or discontinue use of affected devices.
| Google Android (Pixel devices) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912
- Affected
- Android Pixel
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- Products
- android
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N