CVE Vulnerabilities

CVE-2023-21266

Published: Oct 06, 2023 | Modified: Jun 17, 2026
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle11.0 (including)11.0 (including)
AndroidGoogle12.0 (including)12.0 (including)
AndroidGoogle12.1 (including)12.1 (including)
AndroidGoogle13.0 (including)13.0 (including)
Android-framework-23Ubuntubionic*
Android-framework-23Ubuntudevel*
Android-framework-23Ubuntuesm-apps/bionic*
Android-framework-23Ubuntuesm-apps/focal*
Android-framework-23Ubuntuesm-apps/jammy*
Android-framework-23Ubuntuesm-apps/noble*
Android-framework-23Ubuntufocal*
Android-framework-23Ubuntujammy*
Android-framework-23Ubuntulunar*
Android-framework-23Ubuntumantic*
Android-framework-23Ubuntunoble*
Android-framework-23Ubuntuoracular*

References