First published: Wed Dec 08 2021(Updated: )
An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =9.0 | |
Google Android | =10.0 | |
Google Android | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25519 has been rated as a medium severity vulnerability due to the potential for local attackers to bypass access controls.
To fix CVE-2021-25519, ensure that you apply the latest security updates from Google for Android versions 9.0, 10.0, and 11.0.
CVE-2021-25519 affects users of Google Android versions 9.0, 10.0, and 11.0 due to improper access control vulnerabilities.
CVE-2021-25519 enables local attackers to gain unauthorized access to sensitive CPLC information.
Yes, the fix for CVE-2021-25519 is included in the SMR Dec-2021 Release 1 from Google.