PT-2021-13362 · Google · Android

Published

2021-11-01

·

Updated

2023-08-08

·

CVE-2021-0933

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions 9 through 12
Description The issue is related to improper input validation in the onCreate method of certain activities, allowing HTML tags to interfere with a consent dialog. This could lead to remote escalation of privilege, potentially tricking the user into accepting the pairing of a malicious Bluetooth device. User interaction is required for exploitation.
Recommendations For Android versions 9 through 12, update to a version that includes the fix for this issue, as specified in the Android security bulletin.

Fix

Improper Encoding or Escaping of Output

RCE

Weakness Enumeration

Related Identifiers

ASB-A-172251622
CVE-2021-0933

Affected Products

Android