PT-2021-13425 · Google · Android

Published

2021-12-15

·

Updated

2021-12-17

·

CVE-2021-1020

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-12
Description The issue is related to improper input validation in the snoozeNotification function of NotificationListenerService.java. This could allow disabling notifications for an arbitrary user, potentially leading to local escalation of privilege. User interaction is required for exploitation, and user execution privileges are needed.
Recommendations For Android version Android-12, update to a version that includes the fix for this issue, as specified by the Android security bulletin. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-1020

Affected Products

Android