VDB

CVE-2021-0524

CVE-2021-0524 PUBLISHED CVSS 5.5 MEDIUM

In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-180418334

EPSS 0.11% · 1.5th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.11%
1.5th percentile

Affected Products

VendorProductVersions
n/aAndroidAndroid-12
googleandroid12.0

Timeline

  • Feb 11, 2022 CVE Published
  • Feb 13, 2022 EPSS Score
  • Feb 19, 2022 EPSS Score
  • Apr 6, 2022 EPSS Score
  • May 29, 2022 EPSS Score
  • Jul 21, 2022 EPSS Score
  • Sep 11, 2022 EPSS Score
  • Nov 3, 2022 EPSS Score
  • Dec 25, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 8, 2023 EPSS Score
  • May 31, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›