CVE-2021-0396 is a critical out-of-bounds write vulnerability affecting Android versions 8.1 through 11, specifically within the Builtins::Generate_ArgumentsAdaptorTrampoline function. This flaw, rated 9.8 CVSS (Critical), allows for remote code execution without user interaction or additional privileges, posing a significant risk to affected devices. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered considerable community attention with 11 mentions and media coverage. Patches were released in the March 2021 Android updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.1CPE matchmatch criteria | cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.