First published: Tue Jan 04 2022(Updated: )
In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-194105348
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =9.0 | |
Android | =10.0 | |
Android | =11.0 | |
Android | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39623 is classified as a high-severity vulnerability due to its potential for remote escalation of privilege.
To fix CVE-2021-39623, ensure that your device is updated to the latest version of the Android operating system.
CVE-2021-39623 affects Android versions 9.0, 10.0, 11.0, and 12.0.
CVE-2021-39623 is an out of bounds write vulnerability that can lead to potential privilege escalation.
No, user interaction is not needed for the exploitation of CVE-2021-39623.