CVE-2021-0505: High severity Google Android vulnerability
Published Jun 7, 2021
·Updated
In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179975048
Affected Software
2 affected components
Google Android=11.0
Google Android
Remediation
Patch Available
Event History
Jun 7, 2021
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Jun 21, 2021
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs local access with low privileges. No user interaction or additional execution privileges are required.
2
What is the security impact if exploitation succeeds?
An attacker may be able to disable an always-on VPN, resulting in local escalation of privilege. The CVSS vector indicates high impact to confidentiality, integrity, and availability.
3
Which Android release is identified as affected?
The affected version listed is Android 11.
4
Is a fix available?
Yes. A patch is available.