CVE-2021-0513

In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of privilege via hidden services with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-156090809
References
Link Resource
https://source.android.com/security/bulletin/2021-06-01 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-269 CWE-862

23 Jun 2021, 18:02

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8
CWE CWE-269
References (MISC) https://source.android.com/security/bulletin/2021-06-01 - (MISC) https://source.android.com/security/bulletin/2021-06-01 - Patch, Vendor Advisory
CPE cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*

21 Jun 2021, 17:35

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-21 17:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-0513

Mitre link : CVE-2021-0513

CVE.ORG link : CVE-2021-0513


JSON object : View

Products Affected

google

  • android
CWE
CWE-862

Missing Authorization