First published: Mon Dec 06 2021(Updated: )
In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-189942532
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =11.0 | |
Android | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-0956 has a high severity level due to its potential for remote escalation of privilege.
To address CVE-2021-0956, ensure that your device is updated to the latest security patch provided by Google for Android 11.0 and 12.0.
CVE-2021-0956 affects Google Android versions 11.0 and 12.0.
No, user interaction is not needed for the exploitation of CVE-2021-0956.
CVE-2021-0956 is an out of bounds write vulnerability in the NfcTag component.