PT-2022-11064 · Google · Android
Published
2022-03-30
·
Updated
2022-04-05
·
CVE-2021-39787
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions Android-12L
Description
In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Recommendations
For Android version Android-12L, update to a version that includes the fix for this issue, as identified by Android ID: A-202506934.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android