{"id":"ASB-A-172939189","details":"In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.","aliases":["A-172939189","CVE-2021-0481"],"modified":"2026-04-17T15:55:28.020024Z","published":"2021-05-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2021-05-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/apps/Settings/+/d4f04398c71f67bc13f85e098e1dc71d840c1a4a"}],"affected":[{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.1:0"},{"fixed":"8.1:2021-05-01"}]}],"versions":["8.1"],"ecosystem_specific":{"spl":"2021-05-01","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Settings/+/6746add669688765a78d98e9a5bbadcaaca5299d","target":{"file":"src/com/android/settings/users/EditUserPhotoController.java"},"id":"ASB-A-172939189-564b2998","digest":{"line_hashes":["68206822101377684983174042021991236107","240043281711594384508559457642088270710","262409900301059725775001025124622875478","39192478889333380379515350386097722860","26686562759318639202346227432672279492","66998193636228404068683326841069128962","3849801015548461379991504931155685973","33006003959185636112581820292898575241"],"threshold":0.9}},{"signature_type":"Function","signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Settings/+/6746add669688765a78d98e9a5bbadcaaca5299d","target":{"file":"src/com/android/settings/users/EditUserPhotoController.java","function":"onActivityResult"},"id":"ASB-A-172939189-cb0b9635","digest":{"length":499,"function_hash":"149681975055593938242602441892048841884"}}],"types":["EoP"],"severity":"High","fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/6746add669688765a78d98e9a5bbadcaaca5299d"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-172939189.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9:0"},{"fixed":"9:2021-05-01"}]}],"versions":["9"],"ecosystem_specific":{"spl":"2021-05-01","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Settings/+/9c0024f455e41566579d963533a26048c7e2587f","target":{"file":"src/com/android/settings/users/EditUserPhotoController.java","function":"onActivityResult"},"id":"ASB-A-172939189-0a788f24","digest":{"length":499,"function_hash":"149681975055593938242602441892048841884"}},{"signature_type":"Line","signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Settings/+/9c0024f455e41566579d963533a26048c7e2587f","target":{"file":"src/com/android/settings/users/EditUserPhotoController.java"},"id":"ASB-A-172939189-6adb1aa0","digest":{"line_hashes":["68206822101377684983174042021991236107","240043281711594384508559457642088270710","262409900301059725775001025124622875478","39192478889333380379515350386097722860","26686562759318639202346227432672279492","66998193636228404068683326841069128962","3849801015548461379991504931155685973","33006003959185636112581820292898575241"],"threshold":0.9}}],"types":["EoP"],"severity":"High","fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/9c0024f455e41566579d963533a26048c7e2587f"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-172939189.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10:0"},{"fixed":"10:2021-05-01"}]}],"versions":["10"],"ecosystem_specific":{"spl":"2021-05-01","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Settings/+/e0f8214e80372b2578a40e37296e8b8180c1443b","target":{"file":"src/com/android/settings/users/EditUserPhotoController.java","function":"onActivityResult"},"id":"ASB-A-172939189-80c1c58e","digest":{"length":499,"function_hash":"149681975055593938242602441892048841884"}},{"signature_type":"Line","signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Settings/+/e0f8214e80372b2578a40e37296e8b8180c1443b","target":{"file":"src/com/android/settings/users/EditUserPhotoController.java"},"id":"ASB-A-172939189-f4f2425e","digest":{"line_hashes":["68206822101377684983174042021991236107","14071267469509202407620832052958066158","78102370905314753477617063382519190125","185794804406414574103969273213109940282","26686562759318639202346227432672279492","66998193636228404068683326841069128962","3849801015548461379991504931155685973","33006003959185636112581820292898575241"],"threshold":0.9}}],"types":["EoP"],"severity":"High","fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/e0f8214e80372b2578a40e37296e8b8180c1443b"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-172939189.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2021-05-01"}]}],"versions":["11"],"ecosystem_specific":{"spl":"2021-05-01","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Settings/+/e36357b20c524e92408f8a955c77624a1e514659","target":{"file":"src/com/android/settings/users/EditUserPhotoController.java"},"id":"ASB-A-172939189-709fbd08","digest":{"line_hashes":["68206822101377684983174042021991236107","14071267469509202407620832052958066158","78102370905314753477617063382519190125","185794804406414574103969273213109940282","26686562759318639202346227432672279492","66998193636228404068683326841069128962","3849801015548461379991504931155685973","33006003959185636112581820292898575241"],"threshold":0.9}},{"signature_type":"Function","signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Settings/+/e36357b20c524e92408f8a955c77624a1e514659","target":{"file":"src/com/android/settings/users/EditUserPhotoController.java","function":"onActivityResult"},"id":"ASB-A-172939189-a4fddd91","digest":{"length":499,"function_hash":"149681975055593938242602441892048841884"}}],"types":["EoP"],"severity":"High","fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/e36357b20c524e92408f8a955c77624a1e514659"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-172939189.json"}}],"schema_version":"1.7.5"}