VDB

CVE-2021-0547

CVE-2021-0547 PUBLISHED CVSS 7.800000190734863 HIGH

In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL handler due to a missing permission check. This could lead to local escalation of privilege that may result in undefined behavior in some HAL implementations with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174151048

EPSS 0.01% · 2.8th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.01%
2.8th percentile

Affected Products

VendorProductVersions
n/aAndroidAndroid-11
googleandroid11.0

Timeline

  • Jun 8, 2021 CVE Published
  • Jun 23, 2021 EPSS Score
  • Aug 22, 2021 EPSS Score
  • Oct 22, 2021 EPSS Score
  • Dec 21, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 20, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 21, 2022 EPSS Score
  • Jun 20, 2022 EPSS Score
  • Aug 21, 2022 EPSS Score
  • Oct 20, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›