First published: Tue Jan 04 2022(Updated: )
In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-189575031
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =10.0 | |
Android | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39628 is classified as a high severity vulnerability due to the potential for local information disclosure.
To fix CVE-2021-39628, users should update their Android devices to the latest version provided by Google.
CVE-2021-39628 can be exploited to disclose notification content on the lockscreen without user interaction.
CVE-2021-39628 affects Android versions 10.0 and 11.0.
Users of Google Android devices running affected versions are at risk of CVE-2021-39628.