High severity7.8NVD Advisory· Published Feb 11, 2022· Updated Jun 17, 2026
CVE-2021-39663
CVE-2021-39663
Description
In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-200682135
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: = Android-10
Patches
Vulnerability mechanics
References
1- source.android.com/security/bulletin/2022-02-01nvdVendor Advisory
News mentions
0No linked articles in our index yet.