CVE-2021-39618: High severity Google Android vulnerability
In multiple methods of EuiccNotificationManager.java, there is a possible way to install existing packages without user consent due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-196855999
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39618?
CVE-2021-39618 has a severity rating of high due to its potential to allow local privilege escalation.
How do I fix CVE-2021-39618?
To mitigate CVE-2021-39618, ensure that your Android device is updated to the latest security patch provided by Google.
What impact does CVE-2021-39618 have on affected Android versions?
CVE-2021-39618 impacts Android versions 9.0 through 12.0, allowing potential unauthorized installation of packages.
Is user interaction required to exploit CVE-2021-39618?
No, user interaction is not needed for exploiting CVE-2021-39618, which makes the vulnerability more dangerous.
What component is affected by CVE-2021-39618?
CVE-2021-39618 affects the EuiccNotificationManager.java component in affected Android versions.