CVE-2021-0599: Medium severity Google Android vulnerability
In scheduleTimeoutLocked of NotificationRecord.java, there is a possible disclosure of a sensitive identifier via broadcasted intent due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-175614289
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0599?
CVE-2021-0599 has a severity rating of medium due to the potential disclosure of sensitive information.
How do I fix CVE-2021-0599?
To mitigate CVE-2021-0599, users should update their Android devices to the latest version that patches this vulnerability.
What is the impact of CVE-2021-0599?
CVE-2021-0599 may allow local information disclosure through exposed sensitive identifiers.
Which Android versions are affected by CVE-2021-0599?
CVE-2021-0599 affects Android versions 8.1, 9.0, 10.0, and 11.0.
Is user interaction required to exploit CVE-2021-0599?
No, exploitation of CVE-2021-0599 does not require user interaction.