CVE-2021-1020
published 2021-12-15CVE-2021-1020: In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper input…
PriorityP336high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.12%
2.3th percentile
In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195111725
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| msrc | microsoft_edge | — | — |
| platform | frameworks_base | >= 12:0 < 12:2021-12-01 | 12:2021-12-01 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c6qm-6524-j252: In snoozeNotification of NotificationListenerService
ghsa_unreviewed·2021-12-16
CVE-2021-1020 [HIGH] CWE-20 GHSA-c6qm-6524-j252: In snoozeNotification of NotificationListenerService
In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195111725
OSV
CVE-2021-1020: In snoozeNotification of NotificationListenerService
osv·2021-12-01
CVE-2021-1020 CVE-2021-1020: In snoozeNotification of NotificationListenerService
In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
Microsoft
Chromium: CVE-2021-37988 Use after free in Profiles
vendor_msrc·2021-10-12·CVSS 8.8
CVE-2021-37988 [HIGH] Chromium: CVE-2021-37988 Use after free in Profiles
Chromium: CVE-2021-37988 Use after free in Profiles
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In y
Microsoft
Chromium: CVE-2021-37985 Use after free in V8
vendor_msrc·2021-10-12·CVSS 8.8
CVE-2021-37985 [HIGH] Chromium: CVE-2021-37985 Use after free in V8
Chromium: CVE-2021-37985 Use after free in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Mi
Microsoft
Chromium: CVE-2021-38002 Use after free in Web Transport
vendor_msrc·2021-10-12·CVSS 9.6
CVE-2021-38002 [CRITICAL] Chromium: CVE-2021-38002 Use after free in Web Transport
Chromium: CVE-2021-38002 Use after free in Web Transport
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.40
10/29/2021
95.0.4638.69
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2021-38000 Insufficient validation of untrusted input in Intents
vendor_msrc·2021-10-12·CVSS 6.1
CVE-2021-38000 [MEDIUM] Chromium: CVE-2021-38000 Insufficient validation of untrusted input in Intents
Chromium: CVE-2021-38000 Insufficient validation of untrusted input in Intents
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that exploits for this vulnerability exist in the wild.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.40
10/29/2021
95.0.4638.69
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Micro
Microsoft
Chromium: CVE-2021-37990 Inappropriate implementation in WebView
vendor_msrc·2021-10-12·CVSS 5.5
CVE-2021-37990 [MEDIUM] Chromium: CVE-2021-37990 Inappropriate implementation in WebView
Chromium: CVE-2021-37990 Inappropriate implementation in WebView
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the b
Microsoft
Chromium: CVE-2021-37994 Inappropriate implementation in iFrame Sandbox
vendor_msrc·2021-10-12·CVSS 6.5
CVE-2021-37994 [MEDIUM] Chromium: CVE-2021-37994 Inappropriate implementation in iFrame Sandbox
Chromium: CVE-2021-37994 Inappropriate implementation in iFrame Sandbox
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version o
Microsoft
Chromium: CVE-2021-37999 Insufficient data validation in New Tab Page
vendor_msrc·2021-10-12·CVSS 6.1
CVE-2021-37999 [MEDIUM] Chromium: CVE-2021-37999 Insufficient data validation in New Tab Page
Chromium: CVE-2021-37999 Insufficient data validation in New Tab Page
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.40
10/29/2021
95.0.4638.69
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of
Microsoft
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
vendor_msrc·2021-10-12·CVSS 4.3
CVE-2021-42307 [MEDIUM] Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
Microsoft Edge (Chromium-based): Microsoft Edge (Chromium-based)
Microsoft: Microsoft
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Microsoft
Chromium: CVE-2021-37983 Use after free in Dev Tools
vendor_msrc·2021-10-12·CVSS 8.8
CVE-2021-37983 [HIGH] Chromium: CVE-2021-37983 Use after free in Dev Tools
Chromium: CVE-2021-37983 Use after free in Dev Tools
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In
Microsoft
Chromium: CVE-2021-37996 Insufficient validation of untrusted input in Downloads
vendor_msrc·2021-10-12·CVSS 5.5
CVE-2021-37996 [MEDIUM] Chromium: CVE-2021-37996 Insufficient validation of untrusted input in Downloads
Chromium: CVE-2021-37996 Insufficient validation of untrusted input in Downloads
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the
Microsoft
Chromium: CVE-2021-37989 Inappropriate implementation in Blink
vendor_msrc·2021-10-12·CVSS 6.5
CVE-2021-37989 [MEDIUM] Chromium: CVE-2021-37989 Inappropriate implementation in Blink
Chromium: CVE-2021-37989 Inappropriate implementation in Blink
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the bro
Microsoft
Chromium: CVE-2021-37982 Use after free in Incognito
vendor_msrc·2021-10-12·CVSS 8.8
CVE-2021-37982 [HIGH] Chromium: CVE-2021-37982 Use after free in Incognito
Chromium: CVE-2021-37982 Use after free in Incognito
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In
Microsoft
Chromium: CVE-2021-37993 Use after free in PDF Accessibility
vendor_msrc·2021-10-12·CVSS 8.8
CVE-2021-37993 [HIGH] Chromium: CVE-2021-37993 Use after free in PDF Accessibility
Chromium: CVE-2021-37993 Use after free in PDF Accessibility
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the brows
Microsoft
Chromium: CVE-2021-37995 Inappropriate implementation in WebApp Installer
vendor_msrc·2021-10-12·CVSS 6.5
CVE-2021-37995 [MEDIUM] Chromium: CVE-2021-37995 Inappropriate implementation in WebApp Installer
Chromium: CVE-2021-37995 Inappropriate implementation in WebApp Installer
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version
Microsoft
Chromium: CVE-2021-37984 Heap buffer overflow in PDFium
vendor_msrc·2021-10-12·CVSS 8.8
CVE-2021-37984 [HIGH] Chromium: CVE-2021-37984 Heap buffer overflow in PDFium
Chromium: CVE-2021-37984 Heap buffer overflow in PDFium
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2021-37991 Race in V8
vendor_msrc·2021-10-12·CVSS 7.5
CVE-2021-37991 [HIGH] Chromium: CVE-2021-37991 Race in V8
Chromium: CVE-2021-37991 Race in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Ed
Microsoft
Chromium: CVE-2021-37987 Use after free in Network APIs
vendor_msrc·2021-10-12·CVSS 8.8
CVE-2021-37987 [HIGH] Chromium: CVE-2021-37987 Use after free in Network APIs
Chromium: CVE-2021-37987 Use after free in Network APIs
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2021-37997 Use after free in Sign-In
vendor_msrc·2021-10-12·CVSS 8.8
CVE-2021-37997 [HIGH] Chromium: CVE-2021-37997 Use after free in Sign-In
Chromium: CVE-2021-37997 Use after free in Sign-In
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.40
10/29/2021
95.0.4638.69
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In yo
Microsoft
Chromium: CVE-2021-38001 Type Confusion in V8
vendor_msrc·2021-10-12·CVSS 8.8
CVE-2021-38001 [HIGH] Chromium: CVE-2021-38001 Type Confusion in V8
Chromium: CVE-2021-38001 Type Confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.40
10/29/2021
95.0.4638.69
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Mi
Microsoft
Chromium: CVE-2021-37998 Use after free in Garbage Collection
vendor_msrc·2021-10-12·CVSS 8.8
CVE-2021-37998 [HIGH] Chromium: CVE-2021-37998 Use after free in Garbage Collection
Chromium: CVE-2021-37998 Use after free in Garbage Collection
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.40
10/29/2021
95.0.4638.69
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the brow
Microsoft
Chromium: CVE-2021-37986 Heap buffer overflow in Settings
vendor_msrc·2021-10-12·CVSS 8.8
CVE-2021-37986 [HIGH] Chromium: CVE-2021-37986 Heap buffer overflow in Settings
Chromium: CVE-2021-37986 Heap buffer overflow in Settings
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
95.0.1020.30
10/21/2021
95.0.4638.54
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-15
Published