PT-2021-13389 · Google · Android

Published

2021-12-15

·

Updated

2023-08-08

·

CVE-2021-0984

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-12
Description In the onNullBinding function of ManagedServices.java, there is a possible permission bypass due to an incorrectly unbound service. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android version Android-12, consider restricting access to the onNullBinding function in ManagedServices.java to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and adjust service binding permissions to prevent potential bypasses.

Fix

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2021-0984

Affected Products

Android