CVE-2021-1034Missing Authorization in Google Android

Severity
3.3LOWNVD
EPSS
0.0%
top 97.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateDec 16

Description

In getLine1NumberForDisplay of PhoneInterfaceManager.java, there is apossible way to determine whether an app is installed, without querypermissions due to a missing permission check. This could lead to localinformation disclosure with no additional execution privileges needed. Userinteraction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193441322

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5google/androidAndroid-12
NVDgoogle/android12.0
Androidplatform/frameworks_base12:012:2021-12-01

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v52j-x783-j885: In getLine1NumberForDisplay of PhoneInterfaceManager2021-12-16
OSV
CVE-2021-1034: In getLine1NumberForDisplay of PhoneInterfaceManager2021-12-01
CVE-2021-1034 — Missing Authorization in Google Android | cvebase