QID 610332

Date Published: 2021-04-07

QID 610332: Google Android April 2021 Security Patch Missing for LGE

Android is a mobile operating system based on a modified version of the Linux kernel and other open source software, designed primarily for touchscreen mobile devices such as smartphones and tablets.

Following security issues were discovered:
CVE-2020-11192 , CVE-2020-11204 , CVE-2020-11218 , CVE-2020-11227 , CVE-2020-11228 , CVE-2021-0430,CVE-2021-0399 , CVE-2020-11223 , CVE-2020-11290 , CVE-2020-11308 , CVE-2020-11309 , CVE-2020-11165 , CVE-2020-11166 , CVE-2020-11171 , CVE-2020-11178 , CVE-2020-11186 , CVE-2020-11188 , CVE-2020-11189 , CVE-2020-11190 , CVE-2020-11194 , CVE-2020-11195 , CVE-2020-11198 , CVE-2020-11199 , CVE-2020-11220 , CVE-2020-11221 , CVE-2020-11222 , CVE-2020-11226 , CVE-2021-0400 , CVE-2021-0426 , CVE-2021-0427 , CVE-2021-0432 , CVE-2021-0438 , CVE-2021-0439 , CVE-2021-0442 , CVE-2021-0443 , CVE-2021-0338 , CVE-2021-0437 , CVE-2021-0436 , CVE-2021-0471 , CVE-2021-0429 , CVE-2021-0433 , CVE-2021-0431 , CVE-2021-0435,CVE-2020-11299 , CVE-2021-0444 , CVE-2021-0446

Affected Products :
G series (G5, G6, G7, G8), V series(V10, V20, V30, V35, V40, V50) , Q Series(Q6, Q8) , X Series(X300, X400, X500, X cam), CV Series(CV1, CV3, CV5, CV7, CV1S, CV7AS), MH(K40, K50, Q60, Q70)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Refer to LGE Security advisory SMR-April-2021 to address this issue and obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SMR-April-2021 Android URL Logo lgsecurity.lge.com/security_updates_mobile.html