{"id":"PUB-A-250573776","details":"In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-250573776","CVE-2023-20975"],"modified":"2026-04-13T15:04:09.269232Z","published":"2023-06-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2023-06-01"}],"affected":[{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13-next:0"},{"fixed":"13-next:2023-06-01"}]}],"versions":["13-next"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/a1ca72224da3a87d3117e764dfea35e03f62a182"],"vanir_signatures":[{"signature_version":"v1","target":{"file":"src/com/android/settings/privacy/EnableContentCapturePreferenceController.java","function":"getAvailabilityStatus"},"deprecated":false,"id":"PUB-A-250573776-5b7f6683","signature_type":"Function","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/a1ca72224da3a87d3117e764dfea35e03f62a182","match_only_versions":["13-next"],"digest":{"length":166,"function_hash":"258326527094683490707070192044831391883"}},{"signature_version":"v1","target":{"file":"src/com/android/settings/privacy/EnableContentCapturePreferenceController.java"},"deprecated":false,"id":"PUB-A-250573776-fc2eddb4","signature_type":"Line","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/a1ca72224da3a87d3117e764dfea35e03f62a182","match_only_versions":["13-next"],"digest":{"threshold":0.9,"line_hashes":["230878898972108947448676599731865036895","29929630303618403406873241733712735071","43171703898393838406260968717756894712","202220144456139908321737172207194654673","141297438035133473302776685006771028195","314980342124334971502357072826993007426","198523617367747830504737027296671495035","321352975154569528164620798525210741119","167566222161009494756955802324480295557"]}}],"types":["EoP"],"spl":"2023-06-01","severity":"Moderate"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-250573776.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2023-06-01"}]}],"versions":["13"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/a1ca72224da3a87d3117e764dfea35e03f62a182"],"vanir_signatures":[{"signature_version":"v1","target":{"file":"src/com/android/settings/privacy/EnableContentCapturePreferenceController.java"},"deprecated":false,"id":"PUB-A-250573776-25881a26","signature_type":"Line","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/a1ca72224da3a87d3117e764dfea35e03f62a182","match_only_versions":["13"],"digest":{"threshold":0.9,"line_hashes":["230878898972108947448676599731865036895","29929630303618403406873241733712735071","43171703898393838406260968717756894712","202220144456139908321737172207194654673","141297438035133473302776685006771028195","314980342124334971502357072826993007426","198523617367747830504737027296671495035","321352975154569528164620798525210741119","167566222161009494756955802324480295557"]}},{"signature_version":"v1","target":{"file":"src/com/android/settings/privacy/EnableContentCapturePreferenceController.java","function":"getAvailabilityStatus"},"deprecated":false,"id":"PUB-A-250573776-f7ef60d9","signature_type":"Function","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/a1ca72224da3a87d3117e764dfea35e03f62a182","match_only_versions":["13"],"digest":{"length":166,"function_hash":"258326527094683490707070192044831391883"}}],"types":["EoP"],"spl":"2023-06-01","severity":"Moderate"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-250573776.json"}}],"schema_version":"1.7.5"}