CVE-2021-0305
Last modified
CVE-2021-0305 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-154015447
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 8.1 | |
| Android | 9.0 | |
| Android | 10.0 |
References
- https://source.android.com/security/bulletin/2021-02-01Patch, Vendor Advisory
- https://source.android.com/security/bulletin/2021-02-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-0305?
How severe is CVE-2021-0305?
How do I fix CVE-2021-0305?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-0298A Race Condition in the 'show chassis pic' command in Junipe…4.7
- CVE-2021-0299An Improper Handling of Exceptional Conditions vulnerability…7.5
- CVE-2021-0301In ged, there is a possible out of bounds write due to a mis…6.7
- CVE-2021-0302In PackageInstaller, there is a possible tapjacking attack d…7.8
- CVE-2021-0303In dispatchGraphTerminationMessage() of packages/services/Ca…7
- CVE-2021-0304In several functions of GlobalScreenshot.java, there is a po…5.5
- CVE-2021-0306In addAllPermissions of PermissionManagerService.java, there…7.8
- CVE-2021-0307In updatePermissionSourcePackage of PermissionManagerService…7.8
- CVE-2021-0308In ReadLogicalParts of basicmbr.cc, there is a possible out …6.8
- CVE-2021-0309In onCreate of grantCredentialsPermissionActivity, there is …5.5
- CVE-2021-0310In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there i…7.8
- CVE-2021-0311In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue…6.5
Are you affected by CVE-2021-0305?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
