7.8
CVSSv3

CVE-2021-0673

Published: 17/12/2021 Updated: 12/07/2022
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05977326; Issue ID: ALPS05977326.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 10.0

google android 11.0

google android 12.0

Recent Articles

How a malicious Android app could covertly turn the DSP in your MediaTek-powered phone into an eavesdropping bug
The Register • Iain Thomson in San Francisco • 24 Nov 2021

Get our weekly newsletter Millions of devices potentially vulnerable, we're told

Check Point Research will today spill the beans on security holes it found within the audio processor firmware in millions of smartphones, which can be potentially exploited by malicious apps to secretly eavesdrop on people. The infosec outfit believes as many as 37 per cent of smartphones globally are vulnerable. The flaws, patches for which were released last month, lie deep within handsets: in the code that controls an audio-processing unit inside system-on-chips designed by Taiwan's MediaTek...