CVE-2021-0327
HIGHAndroid - Local Privilege Escalation via Binder Identity Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-0327. PoCs published by nanopathi.
AI-analyzed exploit summary This repository contains functional exploit code for CVE-2021-0327, targeting Android's autofill framework. The provided test cases demonstrate the vulnerability by manipulating autofill service interactions, potentially leading to privilege escalation or unauthorized data access.
Description
In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-172935267
Exploits (1)
This repository contains functional exploit code for CVE-2021-0327, targeting Android's autofill framework. The provided test cases demonstrate the vulnerability by manipulating autofill service interactions, potentially leading to privilege escalation or unauthorized data access.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H