CVE-2021-0952: Medium severity Google Android vulnerability
In doCropPhoto of PhotoSelectionHandler.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure of user's contacts with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-195748381
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0952?
CVE-2021-0952 has a high severity rating due to its potential for local information disclosure.
How do I fix CVE-2021-0952?
To address CVE-2021-0952, update your device to the latest version of Android provided by the manufacturer.
What systems are affected by CVE-2021-0952?
CVE-2021-0952 affects Android versions 9.0 through 12.0.
What does CVE-2021-0952 exploit?
CVE-2021-0952 exploits a permission bypass through a confused deputy in the PhotoSelectionHandler.
Is user interaction required for CVE-2021-0952?
Yes, CVE-2021-0952 requires user interaction for exploitation.