Security restrictions bypass in Google Android - CVE-2021-39708

 

Security restrictions bypass in Google Android - CVE-2021-39708

Published: March 8, 2022


Vulnerability identifier: #VU61084
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2021-39708
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Google
Affected software:
Google Android

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to unspecified error in the OS kernel. A remote attacker can trick the victim to perform certain actions on the device and execute arbitrary code.

Successful exploitation of the vulnerability may result in full system compromise.


How to mitigate CVE-2021-39708

Install updates from vendor's website.

Sources