
@xiongchun007 你记得 2023 年 pdd 在安卓端集成 CVE-2023-20963 那事吗 …… 你看 今年 还有一个类似功能的 CVE-2026-43284 🤔🤔🤔🤔
Exploitation ongoing with high activity in latest observed window (1 mentions)
Recommended action window: Immediate (within 24h)
NVD description
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-05-04. Apply updates per vendor instructions.
Priority
LOW
Exploitation
ACTIVE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
4 versions affected across 1 product

@xiongchun007 你记得 2023 年 pdd 在安卓端集成 CVE-2023-20963 那事吗 …… 你看 今年 还有一个类似功能的 CVE-2026-43284 🤔🤔🤔🤔

Fact check: True. In 2023, cybersecurity researchers (Lookout, Kaspersky, Dark Navy) analyzed Pinduoduo Android versions (mostly third-party stores) that exploited vulnerabilities like CVE-2023-20963 for privilege escalation. This let the app spy on other apps' activity/notifications and, in targeted cases (e.g., rival group-buying apps in specific regions), hog CPU to cause lag while faking battery stats. Google suspended it from Play Store; PDD removed the code post-exposure.
Post summary
Researchers identified that Pinduoduo Android apps from third‑party stores leveraged CVE-2023-20963 for privilege escalation and spying, prompting Google to suspend the app and Pinduoduo to remove the malicious code.
4 of 4 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| OS | android | 11.0 | - | - | |
| OS | android | 12.0 | - | - | |
| OS | android | 12.1 | - | - | |
| OS | android | 13.0 | - | - |