Loading HuntDB...

Android Pixel Information Disclosure Vulnerability

Added March 5, 2024 Due March 26, 2024 CVE-2023-21237
Overdue Android / Pixel CWE-200

Description

Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information.

Required Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
6 months ago