PT-2023-17747 · Google · Android

Published

2023-03-01

·

Updated

2025-02-21

·

CVE-2023-20959

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-13
Description The issue arises from missing permissions checks in the AddSupervisedUserActivity, allowing guest users to start the activity. This could lead to local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android version Android-13, consider restricting access to the AddSupervisedUserActivity until a patch is available to prevent local escalation of privilege.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

ASB-A-249057848
CVE-2023-20959

Affected Products

Android