CVE-2021-31815 (CNNVD-202104-2040)
中文标题:
Google Android 安全漏洞
英文标题:
GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android allows attackers to obt...
漏洞描述
中文描述:
Google Android是美国~谷歌~开放手持设备联盟(Google)的的一套以Linux为基础的开源操作系统。 Google Android 存在安全漏洞,攻击者可利用该漏洞获取敏感信息。
英文描述:
GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android allows attackers to obtain sensitive information, such as a user's location history, in-person social graph, and (sometimes) COVID-19 infection status, because Rolling Proximity Identifiers and MAC addresses are written to the Android system log, and many Android devices have applications (preinstalled by the hardware manufacturer or network operator) that read system log data and send it to third parties. NOTE: a news outlet (The Markup) states that they received a vendor response indicating that fix deployment "began several weeks ago and will be complete in the coming days."
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| google\/apple_exposure_notifications | * | - | - |
cpe:2.3:a:google:google\/apple_exposure_notifications:*:*:*:*:*:android:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2021-31815 |
2025-11-11 15:20:58 | 2025-11-11 07:36:51 |
| NVD | nvd_CVE-2021-31815 |
2025-11-11 14:57:36 | 2025-11-11 07:45:10 |
| CNNVD | cnnvd_CNNVD-202104-2040 |
2025-11-11 15:10:37 | 2025-11-11 07:56:42 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202104-2040
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.LOW
- cvss_score: 未提取 -> 3.3
- cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- cvss_version: NOT_EXTRACTED -> 3.1
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']