CVE Vulnerabilities

CVE-2021-0952

Published: Dec 15, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.7 MEDIUM
AV:L/AC:M/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In doCropPhoto of PhotoSelectionHandler.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure of users contacts with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-195748381

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle9.0 (including)9.0 (including)
AndroidGoogle10.0 (including)10.0 (including)
AndroidGoogle11.0 (including)11.0 (including)
AndroidGoogle12.0 (including)12.0 (including)

References