CVE-2021-0594: Input Validation
In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validation. This could lead to remote (proximal, NFC) escalation of privilege allowing an attacker to deceive a user into allowing a Bluetooth connection with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-176445224
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0594?
CVE-2021-0594 is considered a medium severity vulnerability due to its ability to bypass user consent for Bluetooth connections.
How do I fix CVE-2021-0594?
To mitigate CVE-2021-0594, users should update their Android devices to the latest version where the vulnerability has been patched.
What type of vulnerability is CVE-2021-0594?
CVE-2021-0594 is a remote escalation of privilege vulnerability that affects the Bluetooth functionality in specific Android versions.
Which Android versions are affected by CVE-2021-0594?
CVE-2021-0594 affects Android versions 8.1, 9.0, 10.0, and 11.0.
Can CVE-2021-0594 be exploited without user interaction?
Yes, CVE-2021-0594 can potentially be exploited remotely, allowing an attacker to deceive the user into allowing a Bluetooth connection without further interaction.