CVE-2021-0981: Input Validation
In enqueueNotificationInternal of NotificationManagerService.java, there is a possible way to run a foreground service without showing a notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-191981182
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Which devices are affected?
The affected product is Google Android running Android 10 or Android 11.
What level of access does an attacker need?
Exploitation requires local access and low privileges. No user interaction or additional execution privileges are required.
What is the practical impact of successful exploitation?
An attacker may be able to run a foreground service without displaying its required notification, resulting in local privilege escalation with high confidentiality, integrity, and availability impact.
Is a fix available?
Yes. A patch is available; the referenced Android security bulletin is dated 2022-07-01.