CVE-2021-1012 is a local information disclosure vulnerability affecting Android 12. It allows an attacker to determine if an app is installed without requiring query permissions, leveraging a side channel in the onResume function of NotificationAccessDetails.java. Rated as Medium severity with a CVSS score of 5.5, this vulnerability has a low attack complexity and requires no user interaction or additional execution privileges. The primary impact is a high confidentiality loss of local information. There is currently no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has garnered minimal community attention, with no social media mentions or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.0CPE matchmatch criteria | cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.