First published: Mon May 03 2021(Updated: )
In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-172939189
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =8.1 | |
Android | =9.0 | |
Android | =10.0 | |
Android | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-0481 is considered moderate due to the potential for local escalation of privilege.
To mitigate CVE-2021-0481, updating to the latest version of Android or applying the security patches provided by Google is recommended.
CVE-2021-0481 affects Android versions 8.1, 9.0, 10.0, and 11.0.
CVE-2021-0481 facilitates local escalation of privilege through unauthorized file access.
Yes, user interaction is necessary for the exploitation of CVE-2021-0481.