CVE-2021-39619: High severity Google Android vulnerability
Published Feb 7, 2022
·Updated
In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security and privacy settings of app usage due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-197399948
Affected Software
3 affected components
Google Android=11.0
Google Android=12.0
Google Android
Remediation
Patch Available
Event History
Feb 7, 2022
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Feb 11, 2022
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Exploitation requires local access and low privileges. No user interaction or additional execution privileges are needed.
2
Which Android versions are identified as affected?
Android 11 and Android 12 are listed as affected.
3
What is the recommended remediation?
A patch is available. Apply the applicable Android security update containing the fix for Android ID A-197399948.