CVE-2021-0445 describes a local escalation of privilege vulnerability in Android versions 9 and 11, stemming from a confused deputy issue in WelcomeActivity.java that leaves a residual profile. This high-severity vulnerability (CVSS 7.8) requires no user interaction or additional execution privileges for exploitation, allowing an attacker to achieve high impact across confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and it is not listed in CISA's KEV catalog, its low EPSS score and lack of community discussion suggest it is not actively exploited or widely known.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.