CVE-2021-0604: Medium severity Google Android vulnerability
In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible way to share private files over Bluetooth due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-179910660
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0604?
CVE-2021-0604 has been rated as a high severity vulnerability due to the potential for local information disclosure.
How do I fix CVE-2021-0604?
To fix CVE-2021-0604, users should update their Android devices to the latest version where the vulnerability has been patched.
What impact does CVE-2021-0604 have on Android users?
CVE-2021-0604 can allow unauthorized sharing of private files over Bluetooth, posing a risk of information disclosure if exploited.
Is user interaction required to exploit CVE-2021-0604?
Yes, exploitation of CVE-2021-0604 requires user interaction to share files over Bluetooth.
Which versions of Android are affected by CVE-2021-0604?
CVE-2021-0604 affects Android versions 8.1, 9.0, 10.0, and 11.0.