CVE-2021-39674: Use After Free
In btmsecconnected and btmsecdisconnected of btmsec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-201083442
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Devices running Android 10, Android 11, or Android 12 are affected. Exploitation requires local code execution with User-level privileges, so a remote unauthenticated attacker is not indicated by the provided CVSS vector.
Does exploitation require user interaction?
No. The vulnerability can be exploited without user interaction once the attacker has the required local User execution privileges.
What is the impact if exploitation succeeds?
Successful exploitation could allow local escalation of privilege and affect confidentiality, integrity, and availability at a high level.
What should administrators do?
Apply the available patch for Android 10, 11, or 12. The provided data does not identify a configuration workaround for systems that cannot be patched immediately.