CVE-2023-35674
Android Framework
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVSS
- 7.8
- EPSS
- 2.20% 80.8% percentile
- CISA KEV
- Listed
- Published
- 2023.09.12