
Cloud Vulnerability DB
A community-led vulnerabilities database
In the Android operating system's PermissionManagerService.java component, specifically in the addAllPermissions function, a vulnerability was discovered that could allow unauthorized permission access during major Android version upgrades. The vulnerability, identified as CVE-2021-0306, affects Android versions 8.0, 8.1, 9, 10, and 11. This security flaw enables applications to gain the android.permission.ACTIVITY_RECOGNITION permission without requiring user confirmation (Android Bulletin).
The vulnerability exists in the permission management system of Android, specifically affecting the addAllPermissions functionality within PermissionManagerService.java. It allows for a permissions bypass during major Android version upgrades, potentially leading to unauthorized access to the ACTIVITY_RECOGNITION permission. The vulnerability requires no additional execution privileges and can be exploited without user interaction (CVE Mitre).
The vulnerability could lead to local privilege escalation, allowing malicious applications to gain sensitive permissions without user consent. This bypass specifically targets the ACTIVITY_RECOGNITION permission, which could potentially allow unauthorized access to user activity data (Android Bulletin).
The vulnerability can be exploited without requiring user interaction or additional execution privileges. The exploit can be triggered during the process of upgrading between major Android versions (CVE Mitre).
The vulnerability was addressed in the January 2021 Android security bulletin. Users should ensure their Android devices are updated with the latest security patches to mitigate this vulnerability (Android Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."