CVE-2021-39808: Input Validation
Published Apr 4, 2022
·Updated
In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-209966086
Affected Software
4 affected components
Google Android=10.0
Google Android=11.0
Google Android=12.0
Google Android
Remediation
Patch Available
Event History
Apr 4, 2022
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Apr 12, 2022
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionWeakness
Frequently Asked Questions
1
Which devices should be assessed for exposure?
Devices running Android 10, Android 11, or Android 12 should be assessed. The issue affects Google Android.
2
What access does an attacker need to exploit this issue?
An attacker needs local access and low-level privileges on the device. No user interaction is required.
3
What is the available remediation?
A patch is available. Apply the relevant Android security update for the affected device and version.