First published: Mon Jan 04 2021(Updated: )
In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of the user's contacts with User execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-8.0, Android-8.1, Android-9; Android ID: A-162738636.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =8.0 | |
Google Android | =8.1 | |
Google Android | =9.0 | |
Google Android | =10.0 | |
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-0304 is classified as a moderate severity vulnerability.
To resolve CVE-2021-0304, update your Android device to the latest version provided by your manufacturer.
CVE-2021-0304 affects Android versions 8.0, 8.1, 9.0, and 10.0.
CVE-2021-0304 is a local information disclosure vulnerability due to a permission bypass.
No, user interaction is not needed for the exploitation of CVE-2021-0304.