Vulnerability record · CVE-2023-35674 · published 11 September 2023
CVE-2023-35674: Android WindowState logic error allows background activity launch and privilege escalation
Google · Android
A logic error in onCreate of WindowState.java in the Android Framework lets a background activity be launched, enabling local escalation of privilege without additional execution privileges. The flaw is remotely patchable via the September 2023 Android security bulletin, but because it sits in core window management, a successful exploit undermines the app sandbox and can grant an attacker elevated access on the device.
Description
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA KEV with known exploitation and a high CVSS of 7.8, but it requires local access and low privileges, keeping it below critical.
What it is
A logic error in onCreate of WindowState.java in the Android Framework lets a background activity be launched, enabling local escalation of privilege without additional execution privileges. The flaw is remotely patchable via the September 2023 Android security bulletin, but because it sits in core window management, a successful exploit undermines the app sandbox and can grant an attacker elevated access on the device.
Impact
An attacker who can run code locally on the device gains elevated privileges, potentially reaching system-level capabilities and data outside the normal app sandbox. No user interaction is required, so the escalation can occur silently once local access is obtained.
Attack surface
Reached locally through the Android Framework window management path; the CVSS vector AV:L/PR:L/UI:N indicates the attacker needs local access and low privileges but no user interaction. No network vector or authentication bypass is described.
Exploitation
CVE-2023-35674 was added to CISA KEV on 2023-09-13 with a 2023-10-04 remediation due date, indicating known exploitation in the wild; EPSS 30-day probability is 0.02808 (85.8th percentile). No ransomware campaign use is documented.
What to do
- Apply the September 2023 Android security bulletin patch (frameworks/base commit 7428962d3b064ce1122809d87af65099d1129c9e) or a later vendor build.
- If patching is not immediately possible, follow CISA KEV required action and vendor guidance, up to discontinuing use of affected devices.
- Restrict local code execution and untrusted app installation on managed devices to reduce the local access the exploit requires.
- Track device fleet patch levels and prioritize devices that cannot receive the September 2023 or later update.
Detection
- Monitor for unexpected background activity launches or window state anomalies in Android framework logs on managed devices.
- Alert on installation or execution of untrusted apps that could provide the local access needed to trigger the flaw.
- Correlate device patch level against the September 2023 bulletin to identify unpatched endpoints.
- Review local privilege escalation indicators such as processes gaining system-level capabilities without user interaction.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-35674 to the Known Exploited Vulnerabilities catalog on 13 September 2023 as "Android Framework Privilege Escalation Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 4 October 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://android.googlesource.com/platform/frameworks/base/+/7428962d3b064ce1122809d87af65099d1129c9e | Patch |
| https://source.android.com/security/bulletin/2023-09-01 | PatchVendor Advisory |
| https://android.googlesource.com/platform/frameworks/base/+/7428962d3b064ce1122809d87af65099d1129c9e | Patch |
| https://source.android.com/security/bulletin/2023-09-01 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-35674 | Third Party AdvisoryUS Government Resource |
Track CVE-2023-35674 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-35674), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.