CVE-2021-39748

MEDIUM

Android 12L - Local Information Disclosure via Unsafe PendingIntent in InputMethodEditor

Title source: llm
STIX 2.1

Description

In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-203777141

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0010
EPSS Percentile 1.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-276
Status published
Products (1)
google/android 12.1
Published Mar 30, 2022
Tracked Since Feb 18, 2026