CVE-2021-0918: High severity Google Android vulnerability
In gattprocessnotification of gattcl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197536150
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0918?
CVE-2021-0918 has a high severity rating due to the potential for remote code execution over Bluetooth.
How do I fix CVE-2021-0918?
To address CVE-2021-0918, update your Android device to the latest version provided by Google that includes the security patch.
What products are affected by CVE-2021-0918?
CVE-2021-0918 affects Android version 12.0 and possibly earlier versions that utilize the Bluetooth functionality.
Is user interaction required to exploit CVE-2021-0918?
No, exploitation of CVE-2021-0918 does not require user interaction, making it particularly dangerous.
What type of vulnerability is CVE-2021-0918?
CVE-2021-0918 is categorized as a memory corruption vulnerability due to a missing bounds check in the Bluetooth stack.