PT-2021-13141 · Google · Android

Published

2021-07-01

·

Updated

2021-07-16

·

CVE-2021-0486

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Android versions Android-10 through Android-11
Description: The issue is related to a permissions bypass in the onPackageAddedInternal method of PermissionManagerService.java, which could allow access to external storage. This might lead to a local escalation of privilege, requiring User execution privileges. No user interaction is needed for exploitation.
Recommendations: For Android versions Android-10 through Android-11, consider restricting access to external storage until a patch is available. As a temporary workaround, review and restrict permissions related to the PermissionManagerService to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-171430330
CVE-2021-0486

Affected Products

Android