PT-2021-3655 · Google · Android

Published

2021-06-01

·

Updated

2021-06-23

·

CVE-2021-0517

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-11
Description The issue is related to a logic error in the updateCapabilities function of ConnectivityService.java, which can lead to incorrect network state determination. This could result in networking tasks being biased to occur on non-VPN networks, potentially allowing a remote attacker to disclose confidential information without needing additional execution privileges. User interaction is not required for exploitation.
Recommendations For Android version Android-11, consider restricting access to the updateCapabilities function of ConnectivityService.java to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and adjust network settings to ensure that sensitive tasks are routed through VPN networks when necessary.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-179053823
BDU:2021-03881
CVE-2021-0517

Affected Products

Android