VDB
CVE-2021-0547
CVE-2021-0547
PUBLISHED
CVSS 7.800000190734863 HIGH
In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL handler due to a missing permission check. This could lead to local escalation of privilege that may result in undefined behavior in some HAL implementations with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174151048
EPSS 0.01% · 2.8th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.01%
2.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Android | Android-11 |
| android | 11.0 |
Exploit Intelligence
Timeline
- Jun 8, 2021 CVE Published
- Jun 23, 2021 EPSS Score
- Aug 22, 2021 EPSS Score
- Oct 22, 2021 EPSS Score
- Dec 21, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 20, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 21, 2022 EPSS Score
- Jun 20, 2022 EPSS Score
- Aug 21, 2022 EPSS Score
- Oct 20, 2022 EPSS Score