CVE-2021-0511
HIGHAndroid - Local Privilege Escalation via Dex2oat Bytecode Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-0511. PoCs published by Trinadh465.
AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2021-0511, targeting a vulnerability in Android's ART runtime. The exploit leverages a hash collision in the DexCache to trigger a use-after-free condition, potentially leading to arbitrary code execution.
Description
In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-178055795
Exploits (1)
This repository contains a functional exploit PoC for CVE-2021-0511, targeting a vulnerability in Android's ART runtime. The exploit leverages a hash collision in the DexCache to trigger a use-after-free condition, potentially leading to arbitrary code execution.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H