CVE-2021-0932: High severity Google Android vulnerability
Published Nov 1, 2021
·Updated
In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-173025705
Affected Software
2 affected components
Google Android=10.0
Google Android
Event History
Nov 1, 2021
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Dec 15, 2021
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
An attacker needs local access and User-level execution privileges. No user interaction is required.
2
What level of impact could successful exploitation have?
Successful exploitation could let an attacker perform actions as System UI, resulting in local escalation of privilege. The CVSS vector indicates high impact to confidentiality, integrity, and availability.
3
Which Android version is identified as affected?
The provided data identifies Android 10 as affected.