PT-2021-13021 · Google · Android

Published

2021-02-01

·

Updated

2021-02-12

·

CVE-2021-0340

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Android versions Android-10
Description: The issue is related to a possible leak of unredacted location information due to improper input validation in the parseNextBox function of IsoInterface.java. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is required for exploitation.
Recommendations: For Android version Android-10, consider restricting access to location information until a patch is available. As a temporary workaround, avoid using the parseNextBox function of IsoInterface.java until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-134155286
CVE-2021-0340

Affected Products

Android