CVE-2023-20963 is a local privilege escalation vulnerability in Android's android.os.WorkSource handling caused by a parcel mismatch condition. Improper parsing or validation of parcelled data in the WorkSource class can allow a local attacker to confuse object interpretation across IPC boundaries and obtain elevated behavior from privileged components. Public reporting associates the flaw with LaunchAnyWhere-style capability, enabling arbitrary intents to be sent with system privileges. Google states the issue affects Android 11, 12, 12L, and 13 prior to the March 2023 Android security updates.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) exploit for CVE-2023-20963, a vulnerability in Android's WorkSource parcel/unparcel logic. The exploit is implemented as an Android application (APK) written in Java, with a user interface allowing the attacker to specify arbitrary package and activity names. The core exploit logic is in the custom AccountAuthenticator (MyAuthenticator.java), which crafts a malicious Bundle using low-level Parcel manipulation to inject an Intent targeting privileged system components (e.g., the password setup screen in com.android.settings). The MainActivity provides a UI for launching arbitrary Activities in other apps, facilitating exploitation. The exploit targets Android 11, 12, 12L, and 13 devices with security patch levels before March 2023. The repository structure follows standard Android project conventions, with code in the app/src/main/java directory, resources in app/src/main/res, and build scripts for Gradle. The exploit demonstrates privilege escalation and security boundary bypass by leveraging the vulnerable parceling logic to inject Intents into system apps.
This repository is a proof-of-concept (PoC) exploit for CVE-2023-20963, a vulnerability in the Android framework's handling of Bundles and parcel/unparcel logic, specifically related to the WorkSource class. The exploit is implemented as an Android application with a custom AccountAuthenticator service. The main entry point is MainActivity.java, which launches an intent targeting the system's AddAccountSettings activity, passing the app's account type. The core exploit logic resides in MyAuthenticator.java, where a maliciously crafted Bundle is created by manipulating Parcel objects to exploit the WorkSource deserialization flaw. This allows the attacker to launch the ChooseLockPassword activity, effectively bypassing the device's screen lock. The exploit targets Android versions 11, 12, 12L, and 13 prior to the March 2023 security patch. The repository contains standard Android project files, build scripts, and documentation, with the exploit logic concentrated in the Java source files under app/src/main/java/com/example/badparcel/.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Android Framework privilege escalation vulnerability mentioned only in related content.
A Parcel Mismatch vulnerability in Android's android.os.WorkSource class that can be exploited to gain LaunchAnyWhere capability and send arbitrary intents with system privileges.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.