EXPOSURES › CVE-2023-21237
CVE-2023-21237
HIGH ⌖ ON CISA KEV · EXPLOITEDAndroid Pixel devices are vulnerable to information disclosure via misleading UI that hides foreground service notifications.
This local-only vulnerability allows attackers to bypass notification visibility controls to expose sensitive data, posing a risk to DIB organizations relying on Android endpoints for sensitive data handling. While not an RCE, the information disclosure could facilitate further attacks or data exfiltration if combined with other vulnerabilities, necessitating immediate patching and UI hardening.
Shame score — A local UI vulnerability that enables information disclosure rather than remote code execution, with no evidence of active exploitation in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information.