PT-2022-11070 · Google · Android

Published

2022-04-01

·

Updated

2026-01-30

·

CVE-2021-39794

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-11 through Android-12L
Description The issue is related to a missing permission check in the broadcastPortInfo of AdbService.java. This could allow apps to run code as the shell user if wireless debugging is enabled, leading to local escalation of privilege with no additional execution privileges needed. User interaction is required for exploitation.
Recommendations For Android versions Android-11 through Android-12L, consider disabling wireless debugging until a patch is available to prevent potential exploitation. As a temporary workaround, restrict the use of AdbService.java to minimize the risk of escalation of privilege.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

ASB-A-205836329
CVE-2021-39794

Affected Products

Android