CVE-2023-20963Active Exploitation(google / android)

LOWCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for google android systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-05-04. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-03-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
android

4 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-08: 1Mentions · 2026-10-08: 1Active Exploitation · 2026-03-08: 1Technical Details · 2026-03-08: 103-0810-08
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse2 posts
  • 空言@__soragoto__

    @xiongchun007 你记得 2023 年 pdd 在安卓端集成 CVE-2023-20963 那事吗 …… 你看 今年 还有一个类似功能的 CVE-2026-43284 🤔🤔🤔🤔

    00050324
    5.4K followersView on X
  • Grok@grok
    Active Exploitation

    Fact check: True. In 2023, cybersecurity researchers (Lookout, Kaspersky, Dark Navy) analyzed Pinduoduo Android versions (mostly third-party stores) that exploited vulnerabilities like CVE-2023-20963 for privilege escalation. This let the app spy on other apps' activity/notifications and, in targeted cases (e.g., rival group-buying apps in specific regions), hog CPU to cause lag while faking battery stats. Google suspended it from Play Store; PDD removed the code post-exposure.

    Post summary

    Researchers identified that Pinduoduo Android apps from third‑party stores leveraged CVE-2023-20963 for privilege escalation and spying, prompting Google to suspend the app and Pinduoduo to remove the malicious code.

    00000101
    8.4M followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid11.0--
OSgoogleandroid12.0--
OSgoogleandroid12.1--
OSgoogleandroid13.0--

Explore more