CVE-2021-0933: Input Validation
In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to interfere with a consent dialog due to improper input validation. This could lead to remote escalation of privilege, confusing the user into accepting pairing of a malicious Bluetooth device, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-172251622
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0933?
CVE-2021-0933 has been classified as a moderate severity vulnerability.
How do I fix CVE-2021-0933?
To fix CVE-2021-0933, users should update their Android devices to the latest security patch released by Google.
Which versions of Android are affected by CVE-2021-0933?
CVE-2021-0933 affects Android versions 9.0, 10.0, 11.0, and 12.0.
What type of vulnerability is CVE-2021-0933?
CVE-2021-0933 is a remote escalation of privilege vulnerability due to improper input validation.
Can CVE-2021-0933 lead to user confusion?
Yes, CVE-2021-0933 can confuse users into accepting malicious Bluetooth pairing due to a compromised consent dialog.