In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519
Conclusion & alert: CVE-2023-20963 is rated Critical Active Threat (84.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.26%).Core evidence: CISA KEV confirms active exploitation (added 2023-04-13) affecting Android / Framework. a weakness (CWE-295) Unauthenticated remote administrative access may be possible.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Required action: Apply updates per vendor instructions.
Exploit prediction scoring system (EPSS) score for CVE-2023-20963
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).