CVE-2021-0306: High severity Google Android vulnerability
In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITYRECOGNITION permission without user confirmation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11, Android-8.0, Android-8.1, Android-9, Android-10; Android ID: A-154505240.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0306?
CVE-2021-0306 is classified as a high severity vulnerability.
How do I fix CVE-2021-0306?
To fix CVE-2021-0306, update your Android device to a version that contains the security patch addressing this vulnerability.
Which Android versions are affected by CVE-2021-0306?
CVE-2021-0306 affects Android versions 8.0, 8.1, 9.0, 10.0, and 11.0.
What type of vulnerability is CVE-2021-0306?
CVE-2021-0306 is a permissions bypass vulnerability that allows an app to obtain certain permissions without user consent.
What could be a potential consequence of CVE-2021-0306?
CVE-2021-0306 could lead to local escalation of privilege, enabling unauthorized access to activity recognition features.