PT-2021-2472 · Google · Titan M+1
Published
2021-03-01
·
Updated
2021-03-12
·
CVE-2021-0452
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android kernel
Description
The issue is related to the Titan M security module in Android operating systems and is caused by initialization errors. This could lead to local information disclosure with System execution privileges needed, allowing an attacker to gain unauthorized access to protected information. User interaction is not needed for exploitation.
Recommendations
For Android kernel, consider applying a patch or fix to address the uninitialized data issue in the Titan M chip firmware as soon as it becomes available. As a temporary workaround, restrict access to sensitive information and ensure that the system execution privileges are properly configured to minimize the risk of exploitation.
Fix
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Kernel
Titan M