CVE-2023-21364: Google Android

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.

Affected products

  • Google Android: before 14.0 (fixed in 14.0); version 14.0 only

Published 2023-10-30. Last modified 2026-06-17.