PT-2021-13424 · Google · Android
Published
2021-12-15
·
Updated
2022-07-12
·
CVE-2021-1019
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions Android-12
Description
The issue is related to a permission confusion in the
snoozeNotification function of NotificationListenerService.java. This confusion is caused by a misleading user consent dialog, which could lead to local escalation of privilege. The exploitation of this issue requires user interaction and can be executed with User execution privileges.Recommendations
For Android version Android-12, consider restricting or disabling the
snoozeNotification function in NotificationListenerService.java until a proper fix is implemented to avoid potential exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android