← Vulnerability feed

Vulnerability record · CVE-2023-35674 · published 11 September 2023

CVE-2023-35674: Android WindowState logic error allows background activity launch and privilege escalation

Google · Android

A logic error in onCreate of WindowState.java in the Android Framework lets a background activity be launched, enabling local escalation of privilege without additional execution privileges. The flaw is remotely patchable via the September 2023 Android security bulletin, but because it sits in core window management, a successful exploit undermines the app sandbox and can grant an attacker elevated access on the device.

7.8 CVSS 3.1 High CISA KEV since 13 Sep 2023 EPSS 2.6% · top 15.2% CWE-269 · Improper privilege management
7.8CVSS 3.1 base score
2.6%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA KEV with known exploitation and a high CVSS of 7.8, but it requires local access and low privileges, keeping it below critical.

What it is

A logic error in onCreate of WindowState.java in the Android Framework lets a background activity be launched, enabling local escalation of privilege without additional execution privileges. The flaw is remotely patchable via the September 2023 Android security bulletin, but because it sits in core window management, a successful exploit undermines the app sandbox and can grant an attacker elevated access on the device.

Impact

An attacker who can run code locally on the device gains elevated privileges, potentially reaching system-level capabilities and data outside the normal app sandbox. No user interaction is required, so the escalation can occur silently once local access is obtained.

Attack surface

Reached locally through the Android Framework window management path; the CVSS vector AV:L/PR:L/UI:N indicates the attacker needs local access and low privileges but no user interaction. No network vector or authentication bypass is described.

Exploitation

CVE-2023-35674 was added to CISA KEV on 2023-09-13 with a 2023-10-04 remediation due date, indicating known exploitation in the wild; EPSS 30-day probability is 0.02808 (85.8th percentile). No ransomware campaign use is documented.

What to do

  • Apply the September 2023 Android security bulletin patch (frameworks/base commit 7428962d3b064ce1122809d87af65099d1129c9e) or a later vendor build.
  • If patching is not immediately possible, follow CISA KEV required action and vendor guidance, up to discontinuing use of affected devices.
  • Restrict local code execution and untrusted app installation on managed devices to reduce the local access the exploit requires.
  • Track device fleet patch levels and prioritize devices that cannot receive the September 2023 or later update.

Detection

  • Monitor for unexpected background activity launches or window state anomalies in Android framework logs on managed devices.
  • Alert on installation or execution of untrusted apps that could provide the local access needed to trigger the flaw.
  • Correlate device patch level against the September 2023 bulletin to identify unpatched endpoints.
  • Review local privilege escalation indicators such as processes gaining system-level capabilities without user interaction.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-35674 to the Known Exploited Vulnerabilities catalog on 13 September 2023 as "Android Framework Privilege Escalation Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 4 October 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-35674 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-58704Android Cellular Modem improper authorization allows adjacent privilege escalationAndroid's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escala…KEVEPSS 0.59%analysed8.8CVE-2025-48543Android use-after-free allows Chrome sandbox escape to system_serverA use-after-free in multiple Android locations lets an attacker escape the Chrome sandbox and reach the Android system_server process. Because the fl…KEVEPSS 0.54%analysed8.4CVE-2025-48595Android Framework integer overflow enables local code executionAn integer overflow in multiple locations of the Android Framework can be turned into code execution. It allows a local attacker to escalate privileg…KEVEPSS 1.7%analysed7.8CVE-2025-48572Android Framework permissions bypass enables background activity launchMultiple locations in the Android Framework allow activities to be launched from the background because of a permissions bypass, a missing authentica…KEVEPSS 0.26%analysed7.8CVE-2024-32896Android Pixel logic error allows local privilege escalationCVE-2024-32896 is a logic error in Android (CWE-670/CWE-783) that permits a local attacker to bypass intended restrictions and escalate privileges. I…KEVEPSS 3.0%analysed7.8CVE-2024-29748Android Pixel logic error allows local privilege escalationCVE-2024-29748 is a logic error in Android code that permits bypassing a security check, leading to local escalation of privilege. It affects Google …KEVEPSS 0.67%analysed7.8CVE-2023-20963Android WorkSource parcel mismatch local privilege escalationCVE-2023-20963 is a parcel mismatch in Android's WorkSource component that allows a local attacker to escalate privileges without additional executio…KEVEPSS 1.5%analysed7.8CVE-2021-39793Android Mali GPU driver out-of-bounds write in kbase_jd_user_buf_pin_pagesThe Android kernel Mali GPU driver function kbase_jd_user_buf_pin_pages in mali_kbase_mem.c contains a logic error that causes an out-of-bounds write…KEVEPSS 0.69%analysed

Source: NIST National Vulnerability Database (record CVE-2023-35674), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.