PT-2022-10982 · Google · Android

Published

2022-03-01

·

Updated

2022-03-23

·

CVE-2021-39701

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions Android-11 through Android-12
Description The issue is related to improper input validation in the serviceConnection of ControlsProviderLifecycleManager.kt, allowing a service to run in the foreground without notification or permission. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is required for exploitation.
Recommendations For Android versions Android-11 through Android-12, consider restricting the use of the vulnerable serviceConnection in ControlsProviderLifecycleManager.kt to minimize the risk of exploitation. As a temporary workaround, limit the ability of services to run in the foreground without proper notification or permission until a fix is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-212286849
CVE-2021-39701

Affected Products

Android