PT-2021-17092 · Google · Android
Published
2021-02-04
·
Updated
2021-02-08
·
CVE-2021-26687
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LG mobile devices with Android OS versions 8.0 through 10
Description
An issue was discovered in preloaded applications on LG mobile devices where the HostnameVerified default is mishandled.
Recommendations
For Android OS versions 8.0 through 10, consider restricting access to preloaded applications until a patch is available.
As a temporary workaround, consider disabling the mishandled HostnameVerified default in preloaded applications until a fix is provided.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android