CVE-2021-0434
Last modified
CVE-2021-0434 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local escalation of privilege with no additional execution privileges needed. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-167403112
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 9.0 | |
| Android | 10.0 | |
| Android | 11.0 |
References
- https://source.android.com/security/bulletin/2021-11-01Vendor Advisory
- https://source.android.com/security/bulletin/2021-11-01Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-0434?
How severe is CVE-2021-0434?
How do I fix CVE-2021-0434?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-0428In getSimSerialNumber of TelephonyManager.java, there is a p…5.5
- CVE-2021-0429In pollOnce of ALooper.cpp, there is possible memory corrupt…7.8
- CVE-2021-0430In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible o…9.8
- CVE-2021-0431In avrc_msg_cback of avrc_api.cc, there is a possible out of…7.5
- CVE-2021-0432In ClearPullerCacheIfNecessary and ForceClearPullerCache of …7
- CVE-2021-0433In onCreate of DeviceChooserActivity.java, there is a possib…8
- CVE-2021-0435In avrc_proc_vendor_command of avrc_api.cc, there is a possi…7.5
- CVE-2021-0436In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a pos…5.5
- CVE-2021-0437In setPlayPolicy of DrmPlugin.cpp, there is a possible doubl…7.8
- CVE-2021-0438In several functions of InputDispatcher.cpp, WindowManagerSe…7.8
- CVE-2021-0439In setPowerModeWithHandle of com_android_server_power_PowerM…7.8
- CVE-2021-0441In onCreate of PermissionActivity.java, there is a possible …7.3
Are you affected by CVE-2021-0434?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
