{"id":"PUB-A-179461812","details":"In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-179461812","CVE-2021-0567"],"modified":"2026-09-21T16:00:45.521740994Z","published":"2021-06-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2021-06-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/base/+/ba987ca94fdec3a1ada76756b6ac77a1584c9051"}],"affected":[{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2021-06-01"}]}],"versions":["11"],"ecosystem_specific":{"spl":"2021-06-01","types":["EoP"],"vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://android.googlesource.com/platform/frameworks/base/+/ba987ca94fdec3a1ada76756b6ac77a1584c9051","target":{"file":"core/java/android/widget/RemoteViews.java"},"deprecated":false,"digest":{"line_hashes":["48221877078065314032399246798963592162","40571883282913614096753984087443162751","94183366902611697074947187758361598102","188694310945878387646982456014133875907"],"threshold":0.9},"id":"PUB-A-179461812-2676eca6"}],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/ba987ca94fdec3a1ada76756b6ac77a1584c9051"],"severity":"Moderate"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-179461812.json"}}],"schema_version":"1.9.0"}