CVE-2021-0663 describes an out-of-bounds write vulnerability in the audio DSP of Google Android devices, stemming from an incorrect bounds check. This flaw could enable a local attacker to escalate privileges to System execution, requiring no user interaction. While the CVSS score is 6.7 (MEDIUM), indicating high impact on confidentiality, integrity, and availability, exploitation requires high privileges (PR:H). There is no evidence of active exploitation, publicly available exploit code, or inclusion in CISA's KEV catalog. Despite this, the vulnerability has garnered significant community discussion and media coverage, with reports suggesting it could impact a substantial percentage of Android smartphones.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.