CISA: Patch Bug Exploited by Chinese E
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20963 | Local Privilege Escalation in Android Framework (WorkSource Parcel Mismatch) CVE-2023-20963 is a local privilege escalation vulnerability in the Android Framework's WorkSource component, caused by a parcel mismatch (improperly handled parcel data) on devices running Android 11, 12, 12L, and 13. A malicious or compromised app already on the device can trigger the mismatch with no additional execution privileges and no user interaction, making it a low-friction vector once an attacker has any local foothold. Successful exploitation escalates privileges beyond the normal app sandbox - the CVSS 7.8 vector scores high confidentiality, integrity, and availability impact while requiring only low local privileges, indicating substantial system-level access. Any Android device on versions 11 through 13 that has not received the vendor's security patch is potentially affected, which spans a large share of the global smartphone and tablet fleet. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-13 (EPSS currently estimates a 1.5% probability of exploitation in the next 30 days), and related news coverage - including Google's suspension of the Chinese e-commerce app Pinduoduo over malware - links the exploited bug to a broader malware campaign. Do: Apply the latest Android security updates from your device vendor or OEM as soon as they are issued, prioritizing all devices on Android 11, 12, 12L, or 13 - this is the required action CISA lists for this KEV entry. Until patched, avoid installing apps from untrusted sources, since exploitation requires the attacker to already run code locally on the device. Administrators should inventory Android 11-13 endpoints via MDM/EMM and track the fix by Android bug ID A-220302519. | 7.8 | 1% | KEV |
| mass~1-3+ billion devices (Android 11-13 cover the majority of Google's 3+ billion active Android installs) |
Full article309 words · extracted from infosecurity-magazine.com · click to collapse
A leading US security agency has given the government until May 4 to patch a zero-day vulnerability which was allegedly exploited by an e-commerce app to eavesdrop on users.
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2023-20963 to its Known Exploited Vulnerabilities Catalog late last week.
The high severity vulnerability was patched by Google last month after the firm said it may be under “limited, targeted exploitation.”
Read more on malicious Android apps here: Malicious Android Apps Sold For Up to $20,000 on Darknet.
CISA explained that the bug enables attackers to escalate privileges on targeted devices without user interaction.
“Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed,” it noted.
Mobile security company Lookout confirmed late last month that the vulnerability, which has a CVSS score of 7.8, was being exploited by malicious versions of the Pinduoduo Android app. At least two versions of the popular Chinese e-commerce app available from third-party app stores were to blame.
Researchers said this could have enabled threat actors to covertly and remotely control millions of devices, to steal data and install additional malware.
With over 750 million monthly active users, Pinduoduo is one of the world’s most popular destinations for online shopping. The firm has denied its software is malicious, even though the two apps analyzed by researchers were apparently signed with an official key.
The Pinduoduo app has been temporarily pulled from the official Play store, but most Chinese consumers rely on third-party app stores to source their Android downloads.
Although the CISA catalog of known vulnerabilities is designed to force federal government agencies to improve patching processes, it is also strongly recommended that private enterprises use the same tool to help prioritize their efforts in this area.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-patch-bug-exploited-chinese/