CVE-2021-0684: Use After Free
In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-179839665
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0684?
CVE-2021-0684 is classified as a high severity vulnerability due to the potential for local escalation of privilege.
How do I fix CVE-2021-0684?
To fix CVE-2021-0684, ensure that your Android device is updated to the latest version that includes the security patches addressing this vulnerability.
What are the affected Android versions for CVE-2021-0684?
CVE-2021-0684 affects Android versions 8.1, 9.0, 10.0, and 11.0.
Is user interaction required for the exploitation of CVE-2021-0684?
No, user interaction is not required for the exploitation of CVE-2021-0684.
What types of privileges can be escalated by exploiting CVE-2021-0684?
Exploiting CVE-2021-0684 can lead to local escalation of privilege without needing additional execution privileges.