CVE-2021-0584: Input Validation
In verifyBufferObject of Parcel.cpp, there is a possible out of bounds read due to an improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-179289794
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0584?
CVE-2021-0584 has a moderate severity level due to its potential for local information disclosure.
How do I fix CVE-2021-0584?
To fix CVE-2021-0584, update your Android device to a patched version that addresses this vulnerability.
Which versions of Android are affected by CVE-2021-0584?
CVE-2021-0584 affects Android versions 8.1, 9.0, 10.0, and 11.0.
What type of attack does CVE-2021-0584 enable?
CVE-2021-0584 enables an attack that can lead to local information disclosure without requiring additional execution privileges.
Is user interaction needed to exploit CVE-2021-0584?
No, user interaction is not needed to exploit CVE-2021-0584.