CVE-2021-0517: High severity Google Android vulnerability
In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a logic error in the code. This could lead to biasing of networking tasks to occur on non-VPN networks, which could lead to remote information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179053823
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Which devices are affected?
The affected product and version identified here are Google Android 11.
What does an attacker need to exploit this issue?
The issue is remotely exploitable over the network with low attack complexity. It requires no privileges and no user interaction.
What is the practical impact?
A logic error can incorrectly determine network state and bias networking tasks toward non-VPN networks, potentially disclosing information remotely.
Is a fix available?
Yes. A patch is available for this issue.