CVE-2021-39676: Input Validation
In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-197228210
Affected Software
Event History
Frequently Asked Questions
Which devices are in scope?
The affected version listed is Android 11. The provided data does not identify specific device models, vendors, or Android 11 patch levels.
What access would an attacker need to exploit this issue?
Exploitation requires local access and low-level privileges on the device. It does not require user interaction or any additional execution privileges.
Is this exploitable remotely?
The CVSS vector identifies the attack vector as local. The provided information does not indicate a remote exploitation path.