CVE-2021-0523: High severity Google Android vulnerability
In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-174047492
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0523?
CVE-2021-0523 has a moderate severity rating due to its potential for local privilege escalation.
How do I fix CVE-2021-0523?
To fix CVE-2021-0523, ensure your Android device is updated to the latest security patch provided by Google.
What versions of Android are affected by CVE-2021-0523?
CVE-2021-0523 affects Android versions 10.0 and 11.0.
What type of attack is associated with CVE-2021-0523?
CVE-2021-0523 is associated with a tapjacking or overlay attack that could enable unauthorized Wi-Fi scanning.
Is user interaction required to exploit CVE-2021-0523?
Yes, user interaction is necessary for the exploitation of CVE-2021-0523.