In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of the user's contacts with User execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-8.0, Android-8.1, Android-9; Android ID: A-162738636.
                
            References
                    | Link | Resource | 
|---|---|
| https://source.android.com/security/bulletin/2021-01-01 | Vendor Advisory | 
| https://source.android.com/security/bulletin/2021-01-01 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2021-01-11 22:15
Updated : 2024-11-21 05:42
NVD link : CVE-2021-0304
Mitre link : CVE-2021-0304
CVE.ORG link : CVE-2021-0304
JSON object : View
Products Affected
                - android
CWE
                
                    
                        
                        CWE-732
                        
            Incorrect Permission Assignment for Critical Resource
