CVE-2021-0331
Summary
| CVE | CVE-2021-0331 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-10 17:15:00 UTC |
| Updated | 2021-02-12 18:06:00 UTC |
| Description | In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-170731783 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Android Security Bulletin—February 2021 | Android Open Source Project |
MISC |
source.android.com |
Patch, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 610317 Google Android Devices February 2021 Security Patch Missing
- 610318 Google Android February 2021 Security Patch Missing for Huawei EMUI
- 610319 Google Android February 2021 Security Patch Missing for LGE
- 610320 Google Android February 2021 Security Patch Missing for Samsung