Skip to main content

Improper Export of Android Application Components

CVE-2021-25397

Severity Medium
Score 6.8/10

Summary

An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.

  • LOW
  • LOCAL
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • LOW

CWE-926 - Improper Export of Android Application Components

The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.

References

Advisory Timeline

  • Published