PT-2021-13141 · Google · Android
Published
2021-07-01
·
Updated
2021-07-16
·
CVE-2021-0486
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Android versions Android-10 through Android-11
Description:
The issue is related to a permissions bypass in the
onPackageAddedInternal method of PermissionManagerService.java, which could allow access to external storage. This might lead to a local escalation of privilege, requiring User execution privileges. No user interaction is needed for exploitation.Recommendations:
For Android versions Android-10 through Android-11, consider restricting access to external storage until a patch is available.
As a temporary workaround, review and restrict permissions related to the
PermissionManagerService to minimize the risk of exploitation.Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android