In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-163358811
                
            References
                    | Link | Resource | 
|---|---|
| https://source.android.com/security/bulletin/2021-02-01 | Patch Vendor Advisory | 
| https://source.android.com/security/bulletin/2021-02-01 | Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2021-02-10 17:15
Updated : 2024-11-21 05:42
NVD link : CVE-2021-0334
Mitre link : CVE-2021-0334
CVE.ORG link : CVE-2021-0334
JSON object : View
Products Affected
                - android
CWE
                
                    
                        
                        CWE-732
                        
            Incorrect Permission Assignment for Critical Resource
