In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-203777141
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/android-12l | Vendor Advisory |
Configurations
Information
Published : 2022-03-30 09:15
Updated : 2022-04-05 07:10
NVD link : CVE-2021-39748
Mitre link : CVE-2021-39748
JSON object : View
CWE
CWE-276
Incorrect Default Permissions
Products Affected
- android