PT-2021-13336 · Google · Android

Published

2021-11-01

·

Updated

2021-12-17

·

CVE-2021-0889

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions 8.1 through 12
Description The issue is related to a lack of rate limiting in the pairing flow of Android TV, which could lead to silent pairing and potentially allow remote code execution without needing additional execution privileges. User interaction is not required for exploitation.
Recommendations For Android versions 8.1 through 12, apply the necessary patches or updates to address the lack of rate limiting in the pairing flow to prevent potential remote code execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ASB-A-180745296
CVE-2021-0889

Affected Products

Android