← Back

CVE-2021-39625

nvd nist
Published: Jan 14, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.3 / Impact: 5.9
Source: NVD

Description

In showCarrierAppInstallationNotification of EuiccNotificationManager.java, there is a possible way to gain an access to MediaProvider content due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-194695347

Affected (4)

Products: Google: Android
1 product
Android
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 10.0
Version 11.0
Version 12.0
Version 9.0

References (2)

Source: security@android.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.