PT-2021-13353 · Google · Android

Published

2021-11-01

·

Updated

2021-12-17

·

CVE-2021-0923

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-12
Description In the createOrUpdate function of Permission.java, there is a possible way to gain internal permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android version Android-12, consider restricting access to the createOrUpdate function in Permission.java until a patch is available. As a temporary workaround, review and manually verify all permission updates to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-195338390
CVE-2021-0923

Affected Products

Android