PT-2022-10980 · Google · Android

Published

2022-03-01

·

Updated

2022-07-12

·

CVE-2021-39697

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-11 through Android-12
Description The issue is related to a missing permission check in the checkFileUriDestination function of DownloadProvider.java. This could allow bypassing external storage private directories protection, leading to local escalation of privilege. User execution privileges are needed for exploitation, and user interaction is not required.
Recommendations For Android versions Android-11 through Android-12, consider restricting access to the checkFileUriDestination function of DownloadProvider.java until a patch is available. As a temporary workaround, review and enforce proper permission checks for external storage private directories to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-200813547
CVE-2021-39697

Affected Products

Android