First published: Mon Apr 01 2019(Updated: )
In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.1 Android-9. Android ID: A-122034690.
Credit: security@android.com security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | =8.1 | |
Google Android | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2041 has a severity level classified as moderate due to its potential for local privilege escalation.
To fix CVE-2019-2041, update the affected Android devices to the latest security patches provided by Google.
CVE-2019-2041 affects Google Android versions 8.1 and 9.0 on certain devices.
Yes, user interaction is required to exploit CVE-2019-2041 for local privilege escalation.
CVE-2019-2041 is a configuration vulnerability in NFC modules that can result in failing to distinguish individual devices.