CVE-2021-0472
HIGHAndroid - Local Privilege Escalation via App Pinning Permissions Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-0472. PoCs published by nanopathi.
AI-analyzed exploit summary This repository contains functional exploit code for CVE-2021-0472, targeting Android's autofill framework. The test cases demonstrate the vulnerability by manipulating autofill service interactions, potentially leading to privilege escalation or unauthorized data access.
Description
In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-176801033
Exploits (1)
This repository contains functional exploit code for CVE-2021-0472, targeting Android's autofill framework. The test cases demonstrate the vulnerability by manipulating autofill service interactions, potentially leading to privilege escalation or unauthorized data access.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H