LiveActive security incident?Get immediate response
CVE Record

CVE-2021-0544: In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing...

In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169257710

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-0544 is an Android 11 issue in NFC-related system code. A missing bounds check could allow an out-of-bounds write and local privilege escalation. The sources say no user interaction is required, but exploitation requires System execution privileges, so exposure is limited to already-compromised or highly privileged local contexts.

Executive priority

This is not a board-level emergency based on the provided evidence, but it warrants routine patch governance. The impact is privilege escalation, yet the stated prerequisite of System execution privileges limits likely business exposure compared with remotely exploitable flaws.

Technical view

The flaw is in phNxpNciHal_print_res_status in phNxpNciHal.cc. The CVE describes a missing bounds check causing a possible out-of-bounds write. The affected product listed is Android 11, and the Android ID is A-169257710. No CVSS vector, CWE, patch details, or exploit details are provided in the bundle.

Likely exposure

Organizations with Android 11 devices, especially Pixel or devices using the affected Android NFC HAL code, should treat this as potentially relevant. The source bundle does not identify other Android versions, downstream OEM status, or specific device models beyond the Pixel bulletin reference.

Exploitation context

The provided sources do not show active exploitation, and the CVE is not listed as KEV. Exploitation is described as local, requiring System execution privileges, with no user interaction. Evidence is insufficient to claim remote exploitation or broad weaponization.

Researcher notes

The bundle lacks CVSS, CWE, commit, patch diff, and detailed affected-device data. Analysis should stay tied to Android 11, phNxpNciHal.cc, and Android ID A-169257710. Do not infer affected OEMs or exploitability beyond the CVE wording and Pixel bulletin reference.

Mitigation direction

  • Review the June 2021 Android or Pixel security bulletin for vendor-provided fixes.
  • Ensure Android 11 devices have received security updates covering Android ID A-169257710.
  • Check OEM advisories for device-specific backports or patch availability.
  • Prioritize managed devices that remain on Android 11 without current security patch levels.

Validation and detection

  • Inventory Android 11 devices and record their Android security patch level.
  • Confirm whether device OEM bulletins reference CVE-2021-0544 or A-169257710.
  • Verify NFC stack exposure where device builds include the affected Android NFC HAL code.
  • Track unsupported Android 11 devices separately for replacement or compensating controls.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-0544 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aAndroidAndroid-11Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.