Vulnerabilities > Google > Android > 12.0

DATE CVE VULNERABILITY TITLE RISK
2021-12-15 CVE-2021-1010 Missing Authorization vulnerability in Google Android 12.0
In getSigningKeySet of PackageManagerService.java, there is a missing permission check.
local
low complexity
google CWE-862
2.1
2021-12-15 CVE-2021-1011 Missing Authorization vulnerability in Google Android 12.0
In setPackageStoppedState of PackageManagerService.java, there is a missing permission check.
local
low complexity
google CWE-862
2.1
2021-12-15 CVE-2021-1012 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
2.1
2021-12-15 CVE-2021-1013 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
2.1
2021-12-15 CVE-2021-1014 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
2.1
2021-12-15 CVE-2021-1015 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
2.1
2021-12-15 CVE-2021-1016 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 12.0
In onCreate of UsbPermissionActivity.java, there is a possible way to grant an app access to USB without informed user consent due to a tapjacking/overlay attack.
4.4
2021-12-15 CVE-2021-1017 Missing Authorization vulnerability in Google Android 12.0
In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permission check.
local
google CWE-862
4.4
2021-12-15 CVE-2021-1018 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
2.1
2021-12-15 CVE-2021-1019 Unspecified vulnerability in Google Android 12.0
In snoozeNotification of NotificationListenerService.java, there is a possible permission confusion due to a misleading user consent dialog.
local
google
4.4