CVE-2023-21374
📋 TL;DR
This vulnerability allows attackers to bypass factory reset protection on Android devices, potentially gaining unauthorized access to devices that should be locked after a reset. It affects Android devices running vulnerable versions of System UI, requiring no user interaction for exploitation.
💻 Affected Systems
- Android devices with System UI
📦 What is this software?
Android by Google
⚠️ Risk & Real-World Impact
Worst Case
Attacker gains full control of a device that should be protected by factory reset protection, potentially accessing sensitive data or using the device for malicious purposes.
Likely Case
Local attacker bypasses device security to gain elevated privileges and access protected data or features.
If Mitigated
With proper patching, the vulnerability is eliminated; without patching, physical access controls become critical.
🎯 Exploit Status
Requires local access to device; no authentication needed but physical/local access is required.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Android 14 security updates (October 2023 or later)
Vendor Advisory: https://source.android.com/docs/security/bulletin/android-14
Restart Required: Yes
Instructions:
1. Check for Android system updates in Settings > System > System update. 2. Install available security updates. 3. Reboot device after installation.
🔧 Temporary Workarounds
Physical Security Controls
allRestrict physical access to devices to prevent local exploitation
🧯 If You Can't Patch
- Implement strict physical security controls for vulnerable devices
- Consider disabling factory reset protection if not absolutely required
🔍 How to Verify
Check if Vulnerable:
Check Android security patch level in Settings > About phone > Android version. If before October 2023, device may be vulnerable.
Check Version:
Settings > About phone > Android version (GUI only, no CLI command)
Verify Fix Applied:
Verify Android security patch level shows October 2023 or later in Settings > About phone > Android version.
📡 Detection & Monitoring
Log Indicators:
- Unexpected factory reset attempts
- System UI crash logs
- Security bypass events in system logs
Network Indicators:
- None - this is a local exploit
SIEM Query:
Search for system events related to factory reset or security bypass in Android device logs