First published: Mon Mar 07 2022(Updated: )
In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-200164168
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =10.0 | |
Android | =11.0 | |
Android | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39706 has a medium severity rating due to the potential for local privilege escalation.
To remediate CVE-2021-39706, ensure you are running the latest version of Android that addresses the vulnerability.
CVE-2021-39706 affects Android versions 10, 11, and 12.
CVE-2021-39706 requires user interaction for exploitation, allowing local users to potentially escalate privileges.
Exploitation of CVE-2021-39706 could lead to unauthorized access to sensitive credential storage on affected Android devices.