Android 11 Security Release Notes

Published August 25, 2020 | Updated November 19, 2021

This Android Security Release Notes contains details of security vulnerabilities affecting Android devices which are addressed as part of Android 11. Android 11 devices with a security level of 2020-09-01 or later are protected against these issues (Android 11, as released on AOSP, has a default security level of 2020-09-01). To learn how to check a device's security level, see Check and update your Android version.

Android partners are notified of all issues prior to publication. Source code es for these issues are released to the Android Open Source Project (AOSP) repository as part of the Android 11 release.

The severity assessment of issues in these release notes are based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed.

We have had no reports of active customer exploitation or abuse of these newly reported issues. Refer to the Android and Google Play Protect mitigations section for details on the Android security platform protections and Google Play Protect, which improve the security of the Android platform.

Announcements

  • The issues described in this document are addressed as part of Android 11. This information is provided for reference and transparency.
  • We would like to acknowledge and thank the security research community for their continued contributions towards securing the Android ecosystem.

Android and Google service mitigations

This is a summary of the mitigations provided by the Android security platform and service protections such as Google Play Protect. These capabilities reduce the likelihood that security vulnerabilities could be successfully exploited on Android.

  • Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform. We encourage all users to update to the latest version of Android where possible.
  • The Android security team actively monitors for abuse through Google Play Protect and warns users about Potentially Harmful Applications. Google Play Protect is enabled by default on devices with Google Mobile Services, and is especially important for users who install apps from outside of Google Play.

Android 11 vulnerability details

The sections below provide details for security vulnerabilities fixed as part of Android 11. Vulnerabilities are grouped under the component that they affect and include details such as the CVE, associated references, type of vulnerability, and severity.

Android runtime

CVEReferencesTypeSeverity
CVE-2020-0330A-150331085EoPModerate

Framework

CVEReferencesTypeSeverity
CVE-2020-0267A-139128211EoPCritical
CVE-2020-0275A-150507736EoPHigh
CVE-2020-27098A-138791358EoPHigh
CVE-2020-0337A-124329382IDHigh
CVE-2020-27097A-140729426IDHigh
CVE-2020-0333A-73822755RCEModerate
CVE-2019-13734A-147323008EoPModerate
CVE-2019-13752A-147320136EoPModerate
CVE-2019-13753A-147320314EoPModerate
CVE-2020-0130A-123230379EoPModerate
CVE-2020-0277A-148627993EoPModerate
CVE-2020-0341A-144920149EoPModerate
CVE-2020-0345A-144286721EoPModerate
CVE-2020-0366A-138443815EoPModerate
CVE-2019-13751A-147322738IDModerate
CVE-2020-0288A-153995991IDModerate
CVE-2020-0289A-153996872IDModerate
CVE-2020-0290A-153996866IDModerate
CVE-2020-0293A-141455849IDModerate
CVE-2020-0296A-153356209IDModerate
CVE-2020-0297A-155183624IDModerate
CVE-2020-0308A-153654357IDModerate
CVE-2020-0312A-153879099IDModerate
CVE-2020-0317A-119671929IDModerate
CVE-2020-0343A-119672472IDModerate
CVE-2020-0352A-132074310IDModerate
CVE-2020-0372A-119673147IDModerate

Library

CVEReferencesTypeSeverity
CVE-2020-0369A-130231426EoPModerate
CVE-2019-8842A-141551144IDModerate
CVE-2020-0322A-147002540IDModerate
CVE-2020-0323A-146516087IDModerate
CVE-2020-0425A-124000380IDHigh
CVE-2020-0426A-154921790IDModerate
CVE-2020-3898A-111450151IDModerate

Media framework

CVEReferencesTypeSeverity
CVE-2020-0264A-116718596RCEModerate
CVE-2020-0303A-148223229RCEModerate
CVE-2020-0321A-155171907RCEModerate
CVE-2020-0306A-139666480EoPModerate
CVE-2020-0336A-153467444EoPModerate
CVE-2020-0346A-147002762EoPModerate
CVE-2020-0356A-143787559EoPModerate
CVE-2020-0357A-150225569EoPModerate
CVE-2020-0358A-150227563EoPModerate
CVE-2020-0360A-145129456EoPModerate
CVE-2020-0406A-137794014EoPModerate
CVE-2020-0125A-137282168IDModerate
CVE-2020-0270A-145790628IDModerate
CVE-2020-0274A-120781925IDModerate
CVE-2020-0279A-131430997IDModerate
CVE-2020-0314A-154934920IDModerate
CVE-2020-0324A-136660304IDModerate
CVE-2020-0328A-150156131IDModerate
CVE-2020-0329A-63522940IDModerate
CVE-2020-0340A-144901522IDModerate
CVE-2020-0344A-140729887IDModerate
CVE-2020-0355A-141883493IDModerate
CVE-2020-0359A-150303018IDModerate
CVE-2020-0361A-151927433IDModerate
CVE-2020-0364A-137282770IDModerate
CVE-2020-0370A-112051700IDModerate
CVE-2020-0373A-146894086IDModerate
CVE-2020-0287A-141860394DoSModerate
CVE-2020-0301A-124940460DoSModerate
CVE-2020-0320A-129282427DoSModerate
CVE-2020-0332A-124783982DoSModerate
CVE-2020-0351A-124777537DoSModerate
CVE-2020-0353A-124777526DoSModerate
CVE-2020-0362A-123237930DoSModerate
CVE-2020-0363A-132274514DoSModerate

System

CVEReferencesTypeSeverity
CVE-2020-0266A-111086459EoPHigh
CVE-2020-0374A-156251602EoPHigh
CVE-2020-0375A-156253476EoPHigh
CVE-2020-0318A-33646131DoSHigh
CVE-2020-0354A-143604331RCEModerate
CVE-2019-5094A-141639890EoPModerate
CVE-2020-0089A-137015603EoPModerate
CVE-2020-0262A-156353008EoPModerate
CVE-2020-0268A-148294643EoPModerate
CVE-2020-0271A-144507081EoPModerate
CVE-2020-0273A-155646800EoPModerate
CVE-2020-0298A-145129266EoPModerate
CVE-2020-0299A-145130119EoPModerate
CVE-2020-0309A-147227320EoPModerate
CVE-2020-0319A-137868765EoPModerate
CVE-2020-0326A-146453119EoPModerate
CVE-2020-0334A-147995915EoPModerate
CVE-2020-0335A-122361504EoPModerate
CVE-2020-0347A-136658008EoPModerate
CVE-2020-0350A-139424089EoPModerate
CVE-2020-0405A-157475111EoPModerate
CVE-2021-0846A-165596375IDModerate
CVE-2021-0846A-165596375IDModerate
CVE-2020-0263A-154913130IDModerate
CVE-2020-0265A-150155839IDModerate
CVE-2020-0269A-151645626IDModerate
CVE-2020-0272A-130166487IDModerate
CVE-2020-0276A-156253586IDModerate
CVE-2020-0281A-137857778IDModerate
CVE-2020-0282A-144506224IDModerate
CVE-2020-0284A-156253784IDModerate
CVE-2020-0285A-156253479IDModerate
CVE-2020-0286A-150214479IDModerate
CVE-2020-0291A-146032016IDModerate
CVE-2020-0292A-110107252IDModerate
CVE-2020-0295A-155650969IDModerate
CVE-2020-0300A-148736216IDModerate
CVE-2020-0302A-151646375IDModerate
CVE-2020-0304A-151645695IDModerate
CVE-2020-0307A-151645867IDModerate
CVE-2020-0310A-153356468IDModerate
CVE-2020-0311A-153878642IDModerate
CVE-2020-0313A-154917989IDModerate
CVE-2020-0315A-155642026IDModerate
CVE-2020-0316A-154934919IDModerate
CVE-2020-0325A-145079309IDModerate
CVE-2020-0327A-129151407IDModerate
CVE-2020-0331A-147309310IDModerate
CVE-2020-0348A-139188582IDModerate
CVE-2020-0349A-139188779IDModerate
CVE-2020-0365A-137346580DoSModerate

Common questions and answers

This section answers common questions that may occur after reading this bulletin.

1. How do I determine if my device is updated to address these issues?

To learn how to check a device's security level, see Check and update your Android version.

Android 11, as released on AOSP, has a default security level of 2020-09-01. Android devices running Android 11 and with a security level of 2020-09-01 or later address all issues contained in these security release notes.

2. What do the entries in the Type column mean?

Entries in the Type column of the vulnerability details table reference the classification of the security vulnerability.

AbbreviationDefinition
RCERemote code execution
EoPElevation of privilege
IDInformation disclosure
DoSDenial of service
N/AClassification not available

3. What do the entries in the References column mean?

Entries under the References column of the vulnerability details table may contain a prefix identifying the organization to which the reference value belongs.

PrefixReference
A-Android bug ID

Versions

VersionDateNotes
1.0August 25, 2020Security Release Notes published
1.1December 30, 2020Updated issue list
1.2January 27, 2021Updated issue list
1.3November 17, 2021Updated issue list