CVE-2021-0478: High severity Google Android vulnerability
In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught exception. This could lead to local escalation of privilege by running foreground services without notifying the user, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-169255797
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0478?
CVE-2021-0478 is classified as a high severity vulnerability due to its potential for local escalation of privilege.
How do I fix CVE-2021-0478?
To remediate CVE-2021-0478, users should upgrade their Android devices to a patched version containing the latest security updates.
What versions of Android are affected by CVE-2021-0478?
CVE-2021-0478 affects Android versions 8.1, 9.0, 10.0, and 11.0.
What type of attack is enabled by CVE-2021-0478?
CVE-2021-0478 allows an attacker to bypass permissions and run foreground services without user notification.
Is user interaction required to exploit CVE-2021-0478?
No, user interaction is not required to exploit CVE-2021-0478.