CVE-2021-0642: Medium severity Google Android vulnerability
Published Aug 2, 2021
·Updated
In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-185126149
Affected Software
5 affected components
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android=11.0
Google Android
Remediation
Patch Available
Event History
Aug 2, 2021
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Aug 17, 2021
CVE Published
via MITRE·06:28 PM
Data Sourced
via MITRE·06:28 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-0642?
The severity of CVE-2021-0642 is high.
2
How can CVE-2021-0642 be exploited?
CVE-2021-0642 can be exploited through user interaction.
3
What is the vulnerability description of CVE-2021-0642?
CVE-2021-0642 allows local information disclosure without additional execution privileges needed.
4
Which software is affected by CVE-2021-0642?
Google Android versions 8.1, 9.0, 10.0, and 11.0 are affected by CVE-2021-0642.
5
Is there a fix available for CVE-2021-0642?
Yes, please refer to the references provided for the fix.