CVE-2021-39740
MEDIUMAndroid 12L - Local Information Disclosure via Messaging Attachment Restriction Bypass
Title source: llmDescription
In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-209965112
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://source.android.com/security/bulletin/android-12l
Scores
CVSS v3
5.5
EPSS
0.0010
EPSS Percentile
1.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-20
Status
published
Products (1)
google/android
12.1
Published
Mar 30, 2022
Tracked Since
Feb 18, 2026