First published: Mon Dec 06 2021(Updated: )
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06076938; Issue ID: ALPS06076938.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =8.1 | |
Android | =9.0 | |
Android | =10.0 | |
Android | =11.0 | |
MediaTek MT6771 | ||
MediaTek MT8183 | ||
MediaTek MT8385 Firmware | ||
MediaTek MT8788 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-0904 is classified as a high severity vulnerability due to its potential for local escalation of privilege.
To fix CVE-2021-0904, users should apply the latest security patches provided by Google for the affected Android versions.
CVE-2021-0904 affects Android versions 8.1, 9.0, 10.0, and 11.0.
No, user interaction is not needed for the exploitation of CVE-2021-0904.
Exploitation of CVE-2021-0904 may lead to a local privilege escalation, allowing malicious actors to gain system execution privileges.