Unsafe PendingIntent in GlobalScreenshot.java allows for permission bypass and local information disclosure

Unsafe PendingIntent in GlobalScreenshot.java allows for permission bypass and local information disclosure

CVE-2021-0304 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of the user's contacts with User execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-8.0, Android-8.1, Android-9; Android ID: A-162738636.

Learn more about our Cis Benchmark Audit For Google Android.