PT-2021-13232 · Google · Android

Published

2021-07-01

·

Updated

2022-07-12

·

CVE-2021-0590

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Android versions 8.1 through 11
Description: A local information disclosure issue exists due to a missing permission check in the sendNetworkConditionsBroadcast function of NetworkMonitor.java. This allows a privileged app to receive WiFi BSSID and SSID without location permissions, potentially leading to local information disclosure. System execution privileges are needed for exploitation, and user interaction is not required.
Recommendations: For Android versions 8.1 through 11, consider restricting access to the sendNetworkConditionsBroadcast function of NetworkMonitor.java to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ASB-A-175213041
CVE-2021-0590

Affected Products

Android