Vulnerabilities > Google > Android > 12.1

DATE CVE VULNERABILITY TITLE RISK
2022-03-30 CVE-2021-39766 Information Exposure Through Discrepancy vulnerability in Google Android 12.1
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-03-30 CVE-2021-39767 Insecure Default Initialization of Resource vulnerability in Google Android 12.1
In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default value.
local
low complexity
google CWE-1188
7.8
2022-03-30 CVE-2021-39768 Missing Authorization vulnerability in Google Android 12.1
In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing permission check.
local
low complexity
google CWE-862
7.8
2022-03-30 CVE-2021-39769 Incorrect Default Permissions vulnerability in Google Android 12.1
In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check.
local
low complexity
google CWE-276
5.5
2022-03-30 CVE-2021-39770 Incorrect Default Permissions vulnerability in Google Android 12.1
In Framework, there is a possible disclosure of the device owner package due to a missing permission check.
local
low complexity
google CWE-276
5.5
2022-03-30 CVE-2021-39771 Improper Input Validation vulnerability in Google Android 12.1
In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validation.
local
low complexity
google CWE-20
7.8
2022-03-30 CVE-2021-39788 Information Exposure Through Discrepancy vulnerability in Google Android 12.1
In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the device due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-03-30 CVE-2021-39789 Incorrect Authorization vulnerability in Google Android 12.1
In Telecom, there is a possible leak of TTY mode change due to a missing permission check.
local
low complexity
google CWE-863
7.8
2022-03-30 CVE-2021-39790 Incorrect Authorization vulnerability in Google Android 12.1
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check.
local
low complexity
google CWE-863
7.8
2022-03-30 CVE-2021-39791 Information Exposure Through Discrepancy vulnerability in Google Android 12.1
In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5