CVE-2021-39668: High severity Google Android vulnerability
In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-193445603
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Which Android versions are affected?
The issue affects Android 11 and Android 12.
What would an attacker need to exploit this issue?
Exploitation is local and requires user interaction. No additional execution privileges are needed.
What is the potential impact?
An attacker could perform actions as System UI through an Intent Redirect caused by a confused deputy, resulting in local privilege escalation with high confidentiality, integrity, and availability impact.
What should organizations do to remediate the issue?
Apply the available patch referenced in the February 2022 Android security bulletin.