CVE-2021-0956: Critical severity Google Android vulnerability
In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-189942532
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0956?
CVE-2021-0956 has a high severity level due to its potential for remote escalation of privilege.
How do I fix CVE-2021-0956?
To address CVE-2021-0956, ensure that your device is updated to the latest security patch provided by Google for Android 11.0 and 12.0.
What devices are affected by CVE-2021-0956?
CVE-2021-0956 affects Google Android versions 11.0 and 12.0.
Is user interaction required for exploiting CVE-2021-0956?
No, user interaction is not needed for the exploitation of CVE-2021-0956.
What type of vulnerability is CVE-2021-0956?
CVE-2021-0956 is an out of bounds write vulnerability in the NfcTag component.