Aller au contenu

Fiche vulnérabilité

CVE-2021-0932 : faille élevée google android (CVSS 7.8)

Description

In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-173025705

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
15 déc. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • google android

Références

Rechercher une autre vulnérabilité dans la base CVE