First published: Mon Apr 04 2022(Updated: )
In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persistent denial of service in the file picker with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-215002587
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =11.0 | |
Google Android | =12.0 | |
Google Android | =12.1 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39804 has been classified as a medium severity vulnerability due to its potential for remote persistent denial of service.
To fix CVE-2021-39804, ensure that you update your Android device to the latest version released by Google that addresses this vulnerability.
CVE-2021-39804 affects Android versions 11.0, 12.0, and 12.1.
CVE-2021-39804 enables a possible crash that can lead to remote persistent denial of service through user interaction.
Yes, user interaction is required to exploit the vulnerability identified as CVE-2021-39804.