cbcvebase.
CVE-2021-0430
published 2021-04-13

CVE-2021-0430: In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution via a…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution via a malicious NFC packet with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-178725766

Affected

6 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
platformsystem_nfc>= 10:0 < 10:2021-04-0110:2021-04-01
platformsystem_nfc>= 11:0 < 11:2021-04-0111:2021-04-01