CVE-2021-0522: Use After Free
In ConnectionHandler::SdpCb of connectionhandler.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-174182139
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Which Android versions are affected?
Devices running Android 9, Android 10, or Android 11 are identified as affected. The issue is in Android's Bluetooth connection handling code.
What does an attacker need to exploit this issue?
An attacker can exploit the issue remotely over the network without authentication, user interaction, or additional execution privileges. The stated impact is disclosure of information through an out-of-bounds read caused by a use-after-free condition.
What should organizations do to remediate the vulnerability?
A patch is available. Apply the relevant Android security update supplied for the affected device.