PT-2021-13362 · Google · Android

CVE-2021-0933

·

Published

2021-11-01

·

Updated

2023-08-08

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions 9 through 12
Description The issue is related to improper input validation in the onCreate method of certain activities, allowing HTML tags to interfere with a consent dialog. This could lead to remote escalation of privilege, potentially tricking the user into accepting the pairing of a malicious Bluetooth device. User interaction is required for exploitation.
Recommendations For Android versions 9 through 12, update to a version that includes the fix for this issue, as specified in the Android security bulletin.

Fix

Improper Encoding or Escaping of Output

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-172251622
CVE-2021-0933

Affected Products

Android