CVE-2021-0475: Use After Free
In onl2capdataind of btifsockl2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-175686168
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0475?
CVE-2021-0475 has a high severity rating as it can lead to remote code execution over Bluetooth.
How do I fix CVE-2021-0475?
To fix CVE-2021-0475, update your Android device to the latest security patch that addresses this vulnerability.
Which versions of Android are affected by CVE-2021-0475?
CVE-2021-0475 affects Android versions 10.0 and 11.0.
Is user interaction required to exploit CVE-2021-0475?
No, user interaction is not needed for exploiting CVE-2021-0475.
What could be the consequence of exploiting CVE-2021-0475?
Exploiting CVE-2021-0475 could lead to memory corruption and allow an attacker to execute arbitrary code on the device.