
Cloud Vulnerability DB
A community-led vulnerabilities database
In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds read vulnerability due to a missing bounds check. This vulnerability, identified as CVE-2021-0431, affects Android versions 8.1, 9, 10, and 11. The vulnerability was discovered and assigned on November 6, 2020, and was publicly disclosed in the April 2021 Android Security Bulletin (Android Bulletin).
The vulnerability exists in the avrc_msg_cback function of the avrc_api.cc file, which is part of Android's Bluetooth AVRCP (Audio/Video Remote Control Profile) implementation. The issue stems from a missing bounds check that could lead to an out-of-bounds read operation. The vulnerability has been tracked internally by Google under Android ID A-174149901 (CVE Mitre).
If exploited, this vulnerability could lead to remote information disclosure to a paired device. The attack requires no additional execution privileges and can be executed without user interaction (CVE Mitre).
The vulnerability can be exploited by a paired Bluetooth device, requiring no user interaction for exploitation. The attacker needs to be within Bluetooth range and successfully paired with the target device to execute the attack (CVE Mitre).
Google addressed this vulnerability in the April 2021 Android Security Bulletin. Users are advised to update their Android devices to the latest available security patch level to protect against this vulnerability (Android Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."