Executive brief
A use-after-free vulnerability in the Android Kernel binder.c driver allows a local malicious application to escalate privileges to the Linux Kernel. The flaw does not require user interaction but necessitates local code execution or a chained vulnerability in a network-facing application.
Affected products
- Google Android -
- Debian Debian Linux 8.0
Timeline
- 2019-10-01: advisory: Android Security Bulletin published
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed