CVE-2021-39676
11.02.2022, 18:15
In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-197228210Enginsight
Vendor | Product | Version |
---|---|---|
android | 11.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration