CVE-2021-0694: High severity Google Android vulnerability
In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-183147114
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Devices running Android 11 are identified as affected. Exploitation is local, so an attacker would need to have a background application present on the device.
What does an attacker need to exploit it?
The attacker needs low privileges through a local application. No user interaction or additional execution privileges are required.
What is the potential impact?
A background application may regain foreground permissions because background restrictions are insufficient. This can result in local escalation of privilege with high confidentiality, integrity, and availability impact.
How can I identify this issue in Android security tracking?
The Android issue identifier is A-183147114. The listed fix is associated with the Android April 2022 security bulletin.