CVE-2021-39794: High severity Google Android vulnerability
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-205836329
Affected Software
Event History
Frequently Asked Questions
Which devices are exposed to the described attack path?
The affected versions listed are Android 11, Android 12, and Android 12L. The attack path requires wireless debugging to be enabled.
Does exploitation require an existing privileged app or remote network access?
No additional execution privileges are needed, but the issue is local rather than remote. Exploitation also requires user interaction.
What can be done while an update is unavailable?
Disable wireless debugging where it is not required. The reported issue is specifically reachable when wireless debugging is enabled.