PT-2021-17092 · Google · Android

Published

2021-02-04

·

Updated

2021-02-08

·

CVE-2021-26687

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LG mobile devices with Android OS versions 8.0 through 10
Description An issue was discovered in preloaded applications on LG mobile devices where the HostnameVerified default is mishandled.
Recommendations For Android OS versions 8.0 through 10, consider restricting access to preloaded applications until a patch is available. As a temporary workaround, consider disabling the mishandled HostnameVerified default in preloaded applications until a fix is provided.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-26687

Affected Products

Android