CVE-2021-39807: High severity Google Android vulnerability
In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-209446496
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Who is exposed to this issue?
Android 10, Android 11, Android 12, and Android 12L devices are affected. Exploitation is performed locally from a Guest account.
What does an attacker need to exploit it?
The attacker needs access to a device Guest account. No user interaction or additional execution privileges are required.
What is the impact of successful exploitation?
A Guest account user may be able to enable NFC because handleNfcStateChanged lacks a required permission check. This results in local escalation of privilege, with high confidentiality, integrity, and availability impact under the supplied CVSS vector.
What should organizations do if affected?
Apply the available patch for this issue. The provided Android issue identifier is A-209446496.