CVE-2023-21383: Google Android

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In Settings, there is a possible way for the user to unintentionally send extra data due to an unclear prompt. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

Affected products

  • Google Android: before 14.0 (fixed in 14.0)

Published 2023-10-30. Last modified 2026-06-17.