First published: Mon Feb 01 2021(Updated: )
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-155287782
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =8.1 | |
Android | =9.0 | |
Android | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-0302 has been classified as having a moderate severity due to the potential for local escalation of privilege.
To fix CVE-2021-0302, it is recommended to update your Android device to the latest available patch version.
CVE-2021-0302 affects Android versions 8.1, 9.0, and 10.0.
CVE-2021-0302 is associated with a possible tapjacking attack due to an insecure default value.
Yes, user interaction is required for the exploitation of CVE-2021-0302.