7.8
CVSSv3

CVE-2023-20963

Published: 24/03/2023 Updated: 28/03/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 11.0

google android 12.0

google android 12.1

google android 13.0

Github Repositories

CVE-2023-20963 PoC (Android WorkSource parcel/unparcel logic mismatch)

BadParcel See Bundle Fengshui for a deep dive on this bug class This repositiory contains PoC for CVE-2023-20963, which is mismatch in the Android WorkSource parcel/unparcel logic The vulnerability is patched on Android's Security Bulletin of March 2023 The exploit should work on devices on AOSP versions 11, 12, 12L, 13 with security patch levels prior to March 2023 Sc

CVE-2023-20963 PoC (Android WorkSource parcel/unparcel logic mismatch)

BadParcel See Bundle Fengshui for a deep dive on this bug class This repositiory contains PoC for CVE-2023-20963, which is mismatch in the Android WorkSource parcel/unparcel logic The vulnerability is patched on Android's Security Bulletin of March 2023 The exploit should work on devices on AOSP versions 11, 12, 12L, 13 with security patch levels prior to March 2023 Sc