PT-2021-13335 · Google · Android
Published
2021-10-01
·
Updated
2021-11-29
·
CVE-2021-0870
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions 8.1 through 11
Description
The issue is related to a possible memory corruption due to a race condition in the
RW SetActivatedTagType function of rw main.cc. This could lead to remote code execution with no additional execution privileges needed. User interaction is not required for exploitation. The problem affects various components, including the operating system, runtime environment, Media Framework, Framework, and System, allowing for privilege escalation, information disclosure, and denial of service.Recommendations
For Android versions 8.1 through 11, update to the latest version that includes the security patches released on October 1 and 5, 2021, to resolve the issue. As a temporary workaround, consider restricting access to vulnerable components until a patch is available.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android