PT-2021-12991 · Google · Android
Published
2021-01-01
·
Updated
2023-08-10
·
CVE-2021-0307
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Android versions Android-10 through Android-11
Description:
The issue is related to a confused deputy in the
updatePermissionSourcePackage function of PermissionManagerService.java, which could lead to a local escalation of privilege. This allows a malicious app to gain access to a dangerous permission without needing additional execution privileges or user interaction.Recommendations:
For Android versions Android-10 through Android-11, consider restricting access to sensitive permissions to minimize the risk of exploitation until a patch is available.
As a temporary workaround, review and restrict the use of automatic runtime permission grants to prevent silent access to dangerous permissions.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android