PT-2021-13331 · Google · Android

Published

2021-10-01

·

Updated

2021-10-26

·

CVE-2021-0708

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions 8.1 through 11
Description The issue is related to a confused deputy in the runDumpHeap function of ActivityManagerShellCommand.java, which could lead to the deletion of system files. This might result in local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android versions 8.1 through 11, update to a version that includes a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-183262161
CVE-2021-0708

Affected Products

Android