PT-2022-11081 · Google · Android

Published

2022-04-01

·

Updated

2022-07-12

·

CVE-2021-39808

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-10 through Android-12
Description The issue is related to improper input validation in the createNotificationChannelGroup function of PreferencesHelper.java. This could allow a service to run in the foreground without notifying the user, potentially leading to local escalation of privilege. No additional execution privileges are needed, and user interaction is not required for exploitation.
Recommendations For Android versions Android-10 through Android-12, consider restricting the use of the createNotificationChannelGroup function in PreferencesHelper.java until a proper fix is applied to prevent services from running in the foreground without user notification.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-209966086
CVE-2021-39808

Affected Products

Android