CVE-2021-0595
HIGHAndroid 8.1-11 - Unauthenticated Work Profile Access via RootWindowContainer Lock Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-0595. PoCs published by pazhanivel07.
AI-analyzed exploit summary This repository contains functional exploit code for CVE-2021-0595, demonstrating an autofill-related vulnerability in Android. The provided test cases manipulate autofill behavior, potentially leading to unauthorized data exposure or manipulation.
Description
In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-177457096
Exploits (1)
This repository contains functional exploit code for CVE-2021-0595, demonstrating an autofill-related vulnerability in Android. The provided test cases manipulate autofill behavior, potentially leading to unauthorized data exposure or manipulation.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H