PT-2021-13230 · Google · Android
Published
2021-07-01
·
Updated
2022-07-12
·
CVE-2021-0588
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Android versions 8.1 through 9
Description:
The issue is related to a missing permission check in the
processInboundMessage function of MceStateMachine.java, which could lead to local information disclosure. This disclosure is possible through SMS and does not require any additional execution privileges or user interaction.Recommendations:
For Android versions 8.1 through 9, consider restricting access to sensitive information until a patch is available. As a temporary workaround, review and enforce strict permission checks for SMS-related functions to minimize the risk of exploitation.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android