PT-2021-11311 · Google · Android

Published

2021-01-22

·

Updated

2021-07-21

·

CVE-2020-27098

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Android version Android-11
Description: In the checkGrantUriPermission function of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations: For Android version Android-11, consider restricting access to sensitive contacts data until a patch is available. As a temporary workaround, review and restrict permissions related to contact access to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-27098

Affected Products

Android