PT-2022-10985 · Google · Android

Published

2022-03-01

·

Updated

2022-03-23

·

CVE-2021-39704

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-10 through Android-12
Description A permissions bypass issue in the deleteNotificationChannelGroup function of NotificationManagerService.java allows a foreground service to run without user notification. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations For Android versions Android-10 through Android-12, consider restricting the use of the deleteNotificationChannelGroup function until a patch is available. As a temporary workaround, review and restrict foreground service permissions to minimize the risk of exploitation.

Fix

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-209965481
CVE-2021-39704

Affected Products

Android