{"id":"PUB-A-170121238","details":"In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-170121238","CVE-2021-0568"],"modified":"2026-09-22T15:22:15.314525410Z","published":"2021-06-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2021-06-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/base/+/9f67940c41eac13a1d6db17d4a6a8637182e7e74"}],"affected":[{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2021-06-01"}]}],"versions":["11"],"ecosystem_specific":{"spl":"2021-06-01","types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/9f67940c41eac13a1d6db17d4a6a8637182e7e74"],"severity":"Moderate"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-170121238.json"}}],"schema_version":"1.9.0"}