CVE-2021-0507: High severity Google Android vulnerability
In handlercmetamsgcmd of btifrc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-181860042
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch A-181860042 - Compensating control
Disable Bluetooth when not in use and avoid pairing with untrusted devices. Turn off device Bluetooth visibility/discovery and restrict incoming Bluetooth connections to known/trusted devices to reduce exposure until the Android patch/advisory A-181860042 has been applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0507?
CVE-2021-0507 has a high severity due to the potential for remote code execution over Bluetooth.
How do I fix CVE-2021-0507?
To fix CVE-2021-0507, ensure your device is updated to the latest version of Android that includes the security patch addressing this vulnerability.
Which Android versions are affected by CVE-2021-0507?
CVE-2021-0507 affects Android versions 8.1, 9.0, 10.0, and 11.0.
Does exploiting CVE-2021-0507 require user interaction?
Exploitation of CVE-2021-0507 does not require any user interaction, making it particularly dangerous.
What is the impact of CVE-2021-0507 on device security?
The impact of CVE-2021-0507 is severe as it allows attackers to execute arbitrary code on affected devices without additional privileges.