PT-2021-13424 · Google · Android

Published

2021-12-15

·

Updated

2022-07-12

·

CVE-2021-1019

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-12
Description The issue is related to a permission confusion in the snoozeNotification function of NotificationListenerService.java. This confusion is caused by a misleading user consent dialog, which could lead to local escalation of privilege. The exploitation of this issue requires user interaction and can be executed with User execution privileges.
Recommendations For Android version Android-12, consider restricting or disabling the snoozeNotification function in NotificationListenerService.java until a proper fix is implemented to avoid potential exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-1019

Affected Products

Android