CVE-2021-0511: Input Validation
In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-178055795
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Which Android versions should be prioritized for assessment?
Devices running the listed Android 9, Android 10, or Android 11 versions are in scope. The provided data does not identify any configuration-based limitation.
What level of attacker access is required?
Exploitation requires local access and low privileges, as reflected by the CVSS vector AV:L/PR:L. It does not require user interaction or additional execution privileges.
What should teams do if they cannot apply the patch immediately?
A patch is available. The provided information does not specify a temporary mitigation or configuration workaround for systems that cannot yet be patched.