CVE-2023-20924
Published on: Not Yet Published
Last Modified on: 02/01/2023 08:16:00 PM UTC
Certain versions of Android from Google contain the following vulnerability:
In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of privilege with physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-240428519References: N/A
- CVE-2023-20924 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.8 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
PHYSICAL | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Pixel Update Bulletin—January 2023 | Android Open Source Project | source.android.com text/html |
![]() |
Related QID Numbers
- 610461 Google Pixel Android January 2023 Security Patch Missing
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Android | - | All | All | All |
- cpe:2.3:o:google:android:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-20924 : In TBD of TBD , there is a possible way to bypass the lockscreen due to Biometric Auth Failure.… twitter.com/i/web/status/1… | 2023-01-26 21:59:07 |