CVE-2021-0598: High severity Google Android vulnerability
In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-180422108
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0598?
CVE-2021-0598 has a moderate severity level that could allow local escalation of privilege.
How do I fix CVE-2021-0598?
To fix CVE-2021-0598, update your Android device to the latest security patch that addresses this vulnerability.
What platforms are affected by CVE-2021-0598?
CVE-2021-0598 affects Android versions 8.1, 9.0, 10.0, and 11.0.
What type of attack is associated with CVE-2021-0598?
CVE-2021-0598 is associated with a tapjacking/overlay attack targeting Bluetooth device pairing.
Is user interaction required to exploit CVE-2021-0598?
Yes, user interaction is needed to exploit CVE-2021-0598.