CVE-2021-0304: Medium severity Google Android vulnerability
In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of the user's contacts with User execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-8.0, Android-8.1, Android-9; Android ID: A-162738636.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0304?
CVE-2021-0304 is classified as a moderate severity vulnerability.
How do I fix CVE-2021-0304?
To resolve CVE-2021-0304, update your Android device to the latest version provided by your manufacturer.
What software versions are affected by CVE-2021-0304?
CVE-2021-0304 affects Android versions 8.0, 8.1, 9.0, and 10.0.
What type of vulnerability is CVE-2021-0304?
CVE-2021-0304 is a local information disclosure vulnerability due to a permission bypass.
Is user interaction required to exploit CVE-2021-0304?
No, user interaction is not needed for the exploitation of CVE-2021-0304.