CVE-2021-0954: High severity Google Android vulnerability
In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-143559931
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Devices running Android 10 or Android 11 are identified as affected. Exploitation is local, so the attacker needs the ability to execute code as a user-level application on the device.
What does an attacker need to exploit it?
The attacker needs User execution privileges and user interaction. The attack relies on a tapjacking or overlay technique to bypass intended interaction in ResolverActivity.
What is the potential impact if exploitation succeeds?
Successful exploitation could allow local escalation of privilege. The reported CVSS vector indicates high potential impact to confidentiality, integrity, and availability.