CVE-2021-0504: Medium severity Google Android vulnerability
Published Jun 7, 2021
·Updated
In avrcparsbrowsersp of avrcparsct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179162665
Affected Software
2 affected components
Google Android=11.0
Google Android
Remediation
Patch Available
Event History
Jun 7, 2021
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Jun 21, 2021
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases are identified as affected?
The provided data identifies Android 11 as affected.
2
What access does an attacker need to exploit this issue?
The issue is exploitable remotely over Bluetooth. It requires no privileges and no user interaction.
3
What is the impact of successful exploitation?
Successful exploitation may disclose information through an out-of-bounds read. The supplied CVSS vector indicates no integrity or availability impact.
4
Is a fix available?
Yes. A patch is available.