CVE-2021-0970: High severity Google Android vulnerability
In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-196970023
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0970?
CVE-2021-0970 has a severity rating that allows for potential local escalation of privilege without requiring additional execution privileges.
How do I fix CVE-2021-0970?
To fix CVE-2021-0970, update your Google Android device to the latest security patch that addresses this vulnerability.
What versions of Android are affected by CVE-2021-0970?
CVE-2021-0970 affects Android versions 9.0, 10.0, 11.0, and 12.0.
Is user interaction required to exploit CVE-2021-0970?
No, user interaction is not needed for the exploitation of CVE-2021-0970.
What components are involved in CVE-2021-0970?
CVE-2021-0970 involves the createFromParcel method in the GpsNavigationMessage.java component.