CVE-2021-0586: High severity Google Android vulnerability
In onCreate of DevicePickerFragment.java, there is a possible way to trick the user to select an unwanted bluetooth device due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-182584940
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-0586?
CVE-2021-0586 is a vulnerability in DevicePickerFragment.java in Google Android that allows for a tapjacking/overlay attack, potentially leading to local escalation of privilege.
What software is affected by CVE-2021-0586?
Google Android versions 8.1, 9.0, 10.0, and 11.0 are affected by CVE-2021-0586.
What is the severity of CVE-2021-0586?
CVE-2021-0586 has a severity score of 7.8, which is considered high.
How can CVE-2021-0586 be exploited?
CVE-2021-0586 can be exploited through a tapjacking/overlay attack by tricking the user to select an unwanted Bluetooth device.
Are additional execution privileges needed to exploit CVE-2021-0586?
No, no additional execution privileges are needed to exploit CVE-2021-0586, but user interaction is required.