CVE-2020-0007: Medium severity Google Android vulnerability
In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-141890807
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0007?
CVE-2020-0007 has a medium severity rating of 5.5 on the CVSS scale.
What type of vulnerability is CVE-2020-0007?
CVE-2020-0007 is an information disclosure vulnerability caused by uninitialized data in heap memory.
How can CVE-2020-0007 be exploited?
CVE-2020-0007 can be exploited locally to disclose sensitive information from the heap without requiring additional execution privileges.
Which versions of Android are affected by CVE-2020-0007?
CVE-2020-0007 affects Android versions starting from Android-8.
Is user interaction required to exploit CVE-2020-0007?
No, user interaction is not needed to exploit CVE-2020-0007.