Back to Database
Status published
Medium
CVE-2021-26277
Security Advisory | PendingIntent hijacking vulnerability in Framework Services
Vulnerability Description
The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-26277
Credits & Attribution
No credits recorded in the NVD database.
More from vivo
View All →CVE-2025-5719
The wallet has an authentication bypass vulnerability that allows access...
Medium
5.1
CVE-2025-15567
Insufficient protection mechanisms in the Health Module may lead to...
Medium
5.1
CVE-2025-15515
The authentication mechanism for a specific feature in the EasyShare...
Medium
6.9
CVE-2025-15509
The SmartRemote module has insufficient restrictions on loading URLs, which may...
High
7.1
CVE-2024-46941
SystemUI component protection settings vulnerability
Medium
4.8
Affected Vendor
vivo
View all reports →Affected Software
Frame service
Vulnerable Versions:
2021.6.30
Timeline
Official Publish:
February 17th, 2023
Last Modified:
March 18th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N