{"id":"ASB-A-180422108","details":"In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.","aliases":["A-180422108","CVE-2021-0598"],"modified":"2026-05-22T15:55:21.353668239Z","published":"2021-09-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2021-09-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/apps/Nfc/+/e08056f8eafdc98e2db27b9936e61225b5e1ea7d"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/apps/Nfc/+/fd697c56b7795a7f0cf50cac55db71a60d5bd357"}],"affected":[{"package":{"name":"platform/packages/apps/Nfc","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.1:0"},{"fixed":"8.1:2021-09-01"}]}],"versions":["8.1"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/Nfc/+/662f5b3fe7eba4ed70abebd53dcd4563089cf7dd","https://android.googlesource.com/platform/packages/apps/Nfc/+/9c56b01c5745252c13c05a2fe39faaef130813e5"],"vanir_signatures":[{"id":"ASB-A-180422108-cecfb396","target":{"file":"src/com/android/nfc/handover/ConfirmConnectActivity.java"},"digest":{"threshold":0.9,"line_hashes":["296836596259220472807285156088569815707","251353598694993409561482738213207804904","242448319632971748835599379515892226753","136108756541527684360426470570335133777","278324471406019200716570849452251027803"]},"source":"https://android.googlesource.com/platform/packages/apps/Nfc/+/662f5b3fe7eba4ed70abebd53dcd4563089cf7dd","deprecated":false,"signature_version":"v1","signature_type":"Line"},{"target":{"function":"onCreate","file":"src/com/android/nfc/handover/ConfirmConnectActivity.java"},"signature_type":"Function","digest":{"length":1613,"function_hash":"128962696814408615060862366236348820039"},"signature_version":"v1","deprecated":false,"id":"ASB-A-180422108-e63a2584","source":"https://android.googlesource.com/platform/packages/apps/Nfc/+/662f5b3fe7eba4ed70abebd53dcd4563089cf7dd"}],"types":["EoP"],"severity":"High","spl":"2021-09-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-180422108.json"}},{"package":{"name":"platform/packages/apps/Nfc","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9:0"},{"fixed":"9:2021-09-01"}]}],"versions":["9"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/Nfc/+/662f5b3fe7eba4ed70abebd53dcd4563089cf7dd","https://android.googlesource.com/platform/packages/apps/Nfc/+/9c56b01c5745252c13c05a2fe39faaef130813e5"],"vanir_signatures":[{"signature_type":"Line","target":{"file":"src/com/android/nfc/handover/ConfirmConnectActivity.java"},"digest":{"threshold":0.9,"line_hashes":["296836596259220472807285156088569815707","251353598694993409561482738213207804904","242448319632971748835599379515892226753","136108756541527684360426470570335133777","278324471406019200716570849452251027803"]},"id":"ASB-A-180422108-450716f4","deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Nfc/+/662f5b3fe7eba4ed70abebd53dcd4563089cf7dd","signature_version":"v1"},{"source":"https://android.googlesource.com/platform/packages/apps/Nfc/+/662f5b3fe7eba4ed70abebd53dcd4563089cf7dd","target":{"function":"onCreate","file":"src/com/android/nfc/handover/ConfirmConnectActivity.java"},"digest":{"length":1613,"function_hash":"128962696814408615060862366236348820039"},"signature_version":"v1","deprecated":false,"signature_type":"Function","id":"ASB-A-180422108-90423ed7"}],"types":["EoP"],"severity":"High","spl":"2021-09-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-180422108.json"}},{"package":{"name":"platform/packages/apps/Nfc","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10:0"},{"fixed":"10:2021-09-01"}]}],"versions":["10"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/Nfc/+/8afc24e296743c5c294444a14da20bc4c44dec6a","https://android.googlesource.com/platform/packages/apps/Nfc/+/9c56b01c5745252c13c05a2fe39faaef130813e5"],"vanir_signatures":[{"source":"https://android.googlesource.com/platform/packages/apps/Nfc/+/8afc24e296743c5c294444a14da20bc4c44dec6a","target":{"function":"onCreate","file":"src/com/android/nfc/handover/ConfirmConnectActivity.java"},"digest":{"length":1613,"function_hash":"128962696814408615060862366236348820039"},"signature_version":"v1","deprecated":false,"signature_type":"Function","id":"ASB-A-180422108-38cabd9d"},{"target":{"file":"src/com/android/nfc/handover/ConfirmConnectActivity.java"},"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["296836596259220472807285156088569815707","251353598694993409561482738213207804904","242448319632971748835599379515892226753","136108756541527684360426470570335133777","278324471406019200716570849452251027803"]},"signature_version":"v1","deprecated":false,"id":"ASB-A-180422108-7bff64a5","source":"https://android.googlesource.com/platform/packages/apps/Nfc/+/8afc24e296743c5c294444a14da20bc4c44dec6a"}],"types":["EoP"],"severity":"High","spl":"2021-09-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-180422108.json"}},{"package":{"name":"platform/packages/apps/Nfc","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2021-09-01"}]}],"versions":["11"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/Nfc/+/8afc24e296743c5c294444a14da20bc4c44dec6a","https://android.googlesource.com/platform/packages/apps/Nfc/+/9c56b01c5745252c13c05a2fe39faaef130813e5"],"vanir_signatures":[{"signature_version":"v1","signature_type":"Function","digest":{"length":1613,"function_hash":"128962696814408615060862366236348820039"},"id":"ASB-A-180422108-5e113c84","deprecated":false,"target":{"function":"onCreate","file":"src/com/android/nfc/handover/ConfirmConnectActivity.java"},"source":"https://android.googlesource.com/platform/packages/apps/Nfc/+/8afc24e296743c5c294444a14da20bc4c44dec6a"},{"target":{"file":"src/com/android/nfc/handover/ConfirmConnectActivity.java"},"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["296836596259220472807285156088569815707","251353598694993409561482738213207804904","242448319632971748835599379515892226753","136108756541527684360426470570335133777","278324471406019200716570849452251027803"]},"signature_version":"v1","deprecated":false,"id":"ASB-A-180422108-9c5fe78b","source":"https://android.googlesource.com/platform/packages/apps/Nfc/+/8afc24e296743c5c294444a14da20bc4c44dec6a"}],"types":["EoP"],"severity":"High","spl":"2021-09-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-180422108.json"}}],"schema_version":"1.7.5"}