CVE-2021-0444: Medium severity Google Android vulnerability
In onActivityResult of QuickContactActivity.java, there is an unnecessary return of an intent. This could lead to local information disclosure of contact data with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-178825358
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0444?
CVE-2021-0444 has a medium severity rating of 5.5 based on the CVSS 3.1 scoring system.
How does CVE-2021-0444 affect Android users?
CVE-2021-0444 could lead to local information disclosure of contact data but requires user interaction for exploitation.
What products are affected by CVE-2021-0444?
CVE-2021-0444 affects various Android versions, including Android 8.1 and Android 11.
Is there a fix available for CVE-2021-0444?
Yes, there is a patch available to address CVE-2021-0444.
What can users do to mitigate the risk of CVE-2021-0444?
Users should update their Android devices to the latest version to apply the available patch for CVE-2021-0444.