CVE-2021-0704: Medium severity Google Android vulnerability
In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, there is a possible way to retrieve accounts from the device without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-179338675
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0704?
CVE-2021-0704 has been classified as a moderate severity vulnerability.
How does CVE-2021-0704 affect Android devices?
CVE-2021-0704 allows unauthorized access to account information on Android devices without proper permissions.
What versions of Android are affected by CVE-2021-0704?
CVE-2021-0704 affects Android versions 9.0, 10.0, and 11.0.
How do I fix CVE-2021-0704?
To mitigate CVE-2021-0704, update to the latest security patch provided by Google for your Android device.
What type of vulnerability is CVE-2021-0704?
CVE-2021-0704 is a permissions bypass vulnerability that can lead to local information disclosure.