CVE-2021-0317: High severity Google Android vulnerability
In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-10, Android-11, Android-8.0, Android-8.1, Android-9; Android ID: A-168319670.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-0317?
CVE-2021-0317 is a vulnerability in createOrUpdate of Permission.java and related code in Android which could lead to local escalation of privilege.
What is the severity of CVE-2021-0317?
CVE-2021-0317 has a severity rating of 7.8 (high).
Which versions of Android are affected by CVE-2021-0317?
Versions Android-10, Android 8.0, 8.1, 9.0, 10.0, and 11.0 of Android are affected by CVE-2021-0317.
Is user interaction needed for exploitation of CVE-2021-0317?
Yes, user interaction is needed for exploitation of CVE-2021-0317.
How can I fix CVE-2021-0317?
To fix CVE-2021-0317, make sure to apply the necessary security patches provided by Google for your specific Android version.