PT-2021-12991 · Google · Android

Published

2021-01-01

·

Updated

2023-08-10

·

CVE-2021-0307

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Android versions Android-10 through Android-11
Description: The issue is related to a confused deputy in the updatePermissionSourcePackage function of PermissionManagerService.java, which could lead to a local escalation of privilege. This allows a malicious app to gain access to a dangerous permission without needing additional execution privileges or user interaction.
Recommendations: For Android versions Android-10 through Android-11, consider restricting access to sensitive permissions to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and restrict the use of automatic runtime permission grants to prevent silent access to dangerous permissions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ASB-A-155648771
CVE-2021-0307

Affected Products

Android