ZeroHour

CVE-2021-39748

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
Description

In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-203777141

Vendors
google
Products
android
Weakness
CWE-276
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.