CVE-2021-39625: High severity Google Android vulnerability
In showCarrierAppInstallationNotification of EuiccNotificationManager.java, there is a possible way to gain an access to MediaProvider content due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-194695347
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39625?
CVE-2021-39625 has a medium severity rating due to the potential local escalation of privilege.
How do I fix CVE-2021-39625?
To fix CVE-2021-39625, ensure that your device is updated to the latest version of Android that addresses this vulnerability.
What software is affected by CVE-2021-39625?
CVE-2021-39625 affects Google Android versions 9.0, 10.0, 11.0, and 12.0.
Is user interaction required to exploit CVE-2021-39625?
Yes, user interaction is required for the exploitation of CVE-2021-39625.
What type of vulnerability is CVE-2021-39625?
CVE-2021-39625 is an unsafe PendingIntent vulnerability that could allow unauthorized access to MediaProvider content.