Executive brief
An out-of-bounds write vulnerability exists in the binder_transaction function of binder.c in the Android Kernel due to an incorrect bounds check. This flaw allows a local attacker to achieve privilege escalation without requiring user interaction.
Affected products
- Google Android Kernel Android kernel
Timeline
- 2020-03-10: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Observed in the wild as part of the AbstractEmu exploit chain.