CVE-2021-0588: Medium severity Google Android vulnerability
Published Jul 7, 2021
·Updated
In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-177238342
Affected Software
3 affected components
Google Android=8.1
Google Android=9.0
Google Android
Event History
Jul 7, 2021
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Jul 14, 2021
CVE Published
via MITRE·01:44 PM
Data Sourced
via MITRE·01:44 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-0588?
CVE-2021-0588 is classified as a high-severity vulnerability due to the potential for SMS disclosure.
2
How do I fix CVE-2021-0588?
To fix CVE-2021-0588, users should update their Android devices to the latest version provided by Google.
3
Which versions of Android are affected by CVE-2021-0588?
CVE-2021-0588 affects Android versions 8.1 and 9.0.
4
What kind of information can be disclosed due to CVE-2021-0588?
CVE-2021-0588 can lead to local information disclosure through SMS messages.
5
Is user interaction required to exploit CVE-2021-0588?
No, user interaction is not needed for the exploitation of CVE-2021-0588.