PT-2022-10987 · Google · Android

Published

2022-03-01

·

Updated

2022-07-12

·

CVE-2021-39706

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions Android-10 through Android-12
Description The issue is related to a missing permission check in the onResume method of CredentialStorage.java. This could allow for the cleanup of credentials storage content, potentially leading to local escalation of privilege without requiring additional execution privileges. User interaction is necessary for exploitation.
Recommendations For Android versions Android-10 through Android-12, consider restricting access to sensitive credential storage until a fix is available. As a temporary workaround, avoid using the affected CredentialStorage.java functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-200164168
CVE-2021-39706

Affected Products

Android