CVE-2021-0316: Critical severity Google Android vulnerability
In avrcparsvendorcmd of avrcparstg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11, Android-8.0, Android-8.1, Android-9, Android-10; Android ID: A-168802990.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0316?
CVE-2021-0316 has a high severity rating due to its potential for remote code execution through Bluetooth without user interaction.
How do I fix CVE-2021-0316?
To fix CVE-2021-0316, update your Android device to a patched version provided in the security updates.
Which Android versions are affected by CVE-2021-0316?
CVE-2021-0316 affects Android versions 8.0 to 11.0.
Can CVE-2021-0316 be exploited without user interaction?
Yes, CVE-2021-0316 can be exploited remotely without any user interaction required.
What could happen if CVE-2021-0316 is exploited?
Exploitation of CVE-2021-0316 could lead to remote code execution, allowing an attacker to execute arbitrary code on the device.