CVE-2021-0302
Last modified
CVE-2021-0302 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-155287782
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 8.1 | |
| Android | 9.0 | |
| Android | 10.0 |
References
- https://source.android.com/security/bulletin/2021-02-01Patch, Vendor Advisory
- https://source.android.com/security/bulletin/2021-02-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-0302?
How severe is CVE-2021-0302?
How do I fix CVE-2021-0302?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-0295A vulnerability in the Distance Vector Multicast Routing Pro…6.1
- CVE-2021-0296The Juniper Networks CTPView server is not enforcing HTTP St…7.4
- CVE-2021-0297A vulnerability in the processing of TCP MD5 authentication …6.5
- CVE-2021-0298A Race Condition in the 'show chassis pic' command in Junipe…4.7
- CVE-2021-0299An Improper Handling of Exceptional Conditions vulnerability…7.5
- CVE-2021-0301In ged, there is a possible out of bounds write due to a mis…6.7
- CVE-2021-0303In dispatchGraphTerminationMessage() of packages/services/Ca…7
- CVE-2021-0304In several functions of GlobalScreenshot.java, there is a po…5.5
- CVE-2021-0305In PackageInstaller, there is a possible tapjacking attack d…7.8
- CVE-2021-0306In addAllPermissions of PermissionManagerService.java, there…7.8
- CVE-2021-0307In updatePermissionSourcePackage of PermissionManagerService…7.8
- CVE-2021-0308In ReadLogicalParts of basicmbr.cc, there is a possible out …6.8
Are you affected by CVE-2021-0302?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
