CVE-2021-0513: High severity Google Android vulnerability
In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of privilege via hidden services with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-156090809
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0513?
CVE-2021-0513 has a severity rating that indicates a possible local escalation of privilege vulnerability.
How do I fix CVE-2021-0513?
To mitigate CVE-2021-0513, users should update their Android device to the latest security patch provided by Google.
Which versions of Android are affected by CVE-2021-0513?
CVE-2021-0513 affects Android versions 8.1, 9.0, 10.0, and 11.0.
What types of attacks can exploit CVE-2021-0513?
CVE-2021-0513 can be exploited through local escalation of privilege via hidden services without requiring additional execution privileges.
Is user interaction required to exploit CVE-2021-0513?
No, user interaction is not required to exploit CVE-2021-0513.