CVE-2021-0983

In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible disclosure of information about installed device/profile owner package name due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-192245204
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*

History

21 Nov 2024, 05:43

Type Values Removed Values Added
References () https://source.android.com/security/bulletin/pixel/2022-06-01 - Vendor Advisory () https://source.android.com/security/bulletin/pixel/2022-06-01 - Vendor Advisory

15 Jun 2022, 14:15

Type Values Removed Values Added
References
  • {'url': 'https://source.android.com/security/bulletin/pixel/2021-12-01', 'name': 'https://source.android.com/security/bulletin/pixel/2021-12-01', 'tags': ['Patch', 'Vendor Advisory'], 'refsource': 'MISC'}
  • (MISC) https://source.android.com/security/bulletin/pixel/2022-06-01 -
Summary In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-192245204 In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible disclosure of information about installed device/profile owner package name due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-192245204

17 Dec 2021, 18:23

Type Values Removed Values Added
CPE cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
References (MISC) https://source.android.com/security/bulletin/pixel/2021-12-01 - (MISC) https://source.android.com/security/bulletin/pixel/2021-12-01 - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 3.3
CWE CWE-200

15 Dec 2021, 19:20

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-15 19:15

Updated : 2024-11-21 05:43


NVD link : CVE-2021-0983

Mitre link : CVE-2021-0983

CVE.ORG link : CVE-2021-0983


JSON object : View

Products Affected

google

  • android
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor