PT-2021-13330 · Google · Android

Published

2021-10-22

·

Updated

2022-07-12

·

CVE-2021-0706

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Android versions prior to Android-11 Android versions 8.1 through Android-10
Description The issue is related to a missing permission check in the startListening method of PluginManagerImpl.java. This could allow disabling arbitrary app components, leading to a local denial of service without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android versions 8.1 through Android-10, consider restricting access to the PluginManagerImpl class until a patch is available. For Android versions prior to Android-11, update to a newer version to mitigate the risk. As a temporary workaround, consider disabling the startListening method of PluginManagerImpl.java to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-193444889
CVE-2021-0706

Affected Products

Android