High severity7.8CISA KEVNVD Advisory· Published Sep 11, 2023· Updated Jun 17, 2026
CVE-2023-35674
CVE-2023-35674
Description
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7Patches
Vulnerability mechanics
References
3- android.googlesource.com/platform/frameworks/base/+/7428962d3b064ce1122809d87af65099d1129c9envdPatch
- source.android.com/security/bulletin/2023-09-01nvdPatchVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.