PT-2021-13335 · Google · Android

Published

2021-10-01

·

Updated

2021-11-29

·

CVE-2021-0870

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions 8.1 through 11
Description The issue is related to a possible memory corruption due to a race condition in the RW SetActivatedTagType function of rw main.cc. This could lead to remote code execution with no additional execution privileges needed. User interaction is not required for exploitation. The problem affects various components, including the operating system, runtime environment, Media Framework, Framework, and System, allowing for privilege escalation, information disclosure, and denial of service.
Recommendations For Android versions 8.1 through 11, update to the latest version that includes the security patches released on October 1 and 5, 2021, to resolve the issue. As a temporary workaround, consider restricting access to vulnerable components until a patch is available.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-192472262
CVE-2021-0870

Affected Products

Android