CVE-2013-7373: Google Android
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.
Affected products
- Google Android: up to and including 4.3.1; version 1.0 only; version 1.1 only; version 1.5 only; version 1.6 only; version 2.0 only; …
Published 2014-04-29. Last modified 2026-06-17.