PT-2021-13362 · Google · Android
Published
2021-11-01
·
Updated
2023-08-08
·
CVE-2021-0933
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions 9 through 12
Description
The issue is related to improper input validation in the
onCreate method of certain activities, allowing HTML tags to interfere with a consent dialog. This could lead to remote escalation of privilege, potentially tricking the user into accepting the pairing of a malicious Bluetooth device. User interaction is required for exploitation.Recommendations
For Android versions 9 through 12, update to a version that includes the fix for this issue, as specified in the Android security bulletin.
Fix
Improper Encoding or Escaping of Output
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android