CVE-2021-0400: Input Validation
In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency services due to improper input validation. This could lead to incorrect reporting of location data to emergency services with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-177561690
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Who is exposed to this issue?
Devices running Android 9, Android 10, or Android 11 are affected. Exploitation requires local access with user-level execution privileges; no user interaction is required.
What is the potential impact of exploitation?
An attacker could cause incorrect location data to be reported to emergency services. The CVSS vector indicates integrity impact without confidentiality or availability impact.
Is a fix available?
Yes. A patch is available, with remediation information included in the April 2021 Android security bulletin and the referenced Android source change.