CVE-2021-0477: High severity Google Android vulnerability
In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-178189250
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Who is exposed to this issue?
Devices running Android 8.1, 9, 10, or 11 are affected. Exploitation requires local access and execution privileges as a user.
Does exploitation require user interaction?
No. The issue can be exploited without user interaction once the attacker has the required local user execution privileges.
What is the impact of successful exploitation?
Successful exploitation could allow a local attacker to bypass permissions and escalate privileges. The CVSS vector indicates potential high impact to confidentiality, integrity, and availability.
What should administrators do?
Apply the available patch from the Android security update information associated with Android ID A-178189250.