Vulnerability record · CVE-2023-20963 · published 24 March 2023
CVE-2023-20963: Android WorkSource parcel mismatch local privilege escalation
Google · Android
CVE-2023-20963 is a parcel mismatch in Android's WorkSource component that allows a local attacker to escalate privileges without additional execution privileges. It affects Android 11, 12, 12L, and 13, and requires no user interaction. Because it is listed in CISA's Known Exploited Vulnerabilities catalog, it should be treated as actively exploited.
Description
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe vulnerability is in CISA KEV with known exploitation, has a high CVSS score of 7.8, and affects widely used Android versions, though it requires local access.
What it is
CVE-2023-20963 is a parcel mismatch in Android's WorkSource component that allows a local attacker to escalate privileges without additional execution privileges. It affects Android 11, 12, 12L, and 13, and requires no user interaction. Because it is listed in CISA's Known Exploited Vulnerabilities catalog, it should be treated as actively exploited.
Impact
A local attacker can gain elevated privileges on the device, potentially accessing data or capabilities beyond their normal app or user permissions. The CVSS vector indicates high confidentiality, integrity, and availability impact.
Attack surface
The vulnerability is local (AV:L) and requires low privileges (PR:L) with no user interaction (UI:N). It is reached by a local app or process on the Android device, not over the network.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2023-04-13, indicating known exploitation in the wild. EPSS probability is low at 0.01465 (72nd percentile), but the KEV listing takes precedence for active exploitation status.
What to do
- Apply the Android security bulletin patch for March 2023 (2023-03-01) or later vendor updates.
- Verify that affected devices are running Android 11, 12, 12L, or 13 with the latest security patch level.
- Restrict installation of untrusted apps and limit local attack surface where feasible.
- Monitor CISA KEV guidance and vendor instructions for required actions.
Detection
- Monitor for anomalous privilege escalation attempts or unexpected process elevation on Android devices.
- Audit WorkSource-related API usage and parcel handling in app logs where available.
- Track device security patch levels to identify unpatched Android 11-13 devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-20963 to the Known Exploited Vulnerabilities catalog on 13 April 2023 as "Android Framework Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 4 May 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://source.android.com/security/bulletin/2023-03-01 | PatchVendor Advisory |
| https://source.android.com/security/bulletin/2023-03-01 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20963 | Third Party AdvisoryUS Government Resource |
Track CVE-2023-20963 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-20963), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.