CVE-2017-0420: Infoleak
An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32615212.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0420?
CVE-2017-0420 has a High severity rating due to its potential for information disclosure.
How does CVE-2017-0420 affect Android applications?
CVE-2017-0420 allows a local malicious application to bypass operating system protections isolating application data.
What versions of Android are affected by CVE-2017-0420?
CVE-2017-0420 affects Android versions from 4.0 to 7.1.1.
How do I fix CVE-2017-0420?
To fix CVE-2017-0420, ensure that your Android device is updated to a patched version provided by Google.
Can CVE-2017-0420 be exploited remotely?
No, CVE-2017-0420 can only be exploited locally by a malicious application on the same device.