CVE-2021-0953: High severity Google Android vulnerability
In setOnClickActivityIntent of SearchWidgetProvider.java, there is a possible way to access contacts and history bookmarks without permission due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-184046278
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0953?
CVE-2021-0953 has a severity rating of moderate due to potential local escalation of privilege.
How do I fix CVE-2021-0953?
To fix CVE-2021-0953, update to the latest version of Android that addresses this vulnerability.
Which versions of Android are affected by CVE-2021-0953?
CVE-2021-0953 affects Android versions 9.0, 10.0, 11.0, and 12.0.
What kind of access does CVE-2021-0953 exploit?
CVE-2021-0953 exploits an unsafe PendingIntent, potentially allowing access to contacts and history bookmarks.
Is user interaction required to exploit CVE-2021-0953?
No, user interaction is not needed to exploit CVE-2021-0953.