CVE-2021-0319: High severity Google Android vulnerability
In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass. This could lead to local escalation of privilege that grants access to nearby MAC addresses, with User execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.0, Android-8.1, Android-9, Android-10, Android-11; Android ID: A-167244818.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0319?
CVE-2021-0319 is classified as a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2021-0319?
To fix CVE-2021-0319, ensure you update your Android device to the latest security patch provided by Google.
What versions of Android are affected by CVE-2021-0319?
CVE-2021-0319 affects Android versions 8.0, 8.1, 9.0, 10.0, and 11.0.
What type of vulnerability is CVE-2021-0319?
CVE-2021-0319 is a permissions bypass vulnerability related to accessing Bluetooth MAC addresses.
Who is affected by CVE-2021-0319?
Users of affected Android devices may be vulnerable to local escalation of privilege without proper permissions.