CVE-2020-0029: Infoleak
In the WifiConfigManager, there is a possible storage of location history which can only be deleted by triggering a factory reset. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140065828
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
Trigger a factory reset to delete the stored location history in WifiConfigManager.
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0029?
CVE-2020-0029 has been classified with a high severity due to its potential for local information disclosure.
How do I fix CVE-2020-0029?
To mitigate CVE-2020-0029, users should perform a factory reset to delete any stored location history.
What versions of Android are affected by CVE-2020-0029?
CVE-2020-0029 specifically affects Android version 10.0.
Can CVE-2020-0029 be exploited without user interaction?
Yes, CVE-2020-0029 can be exploited without user interaction, as it requires only system execution privileges.
What are the potential risks associated with CVE-2020-0029?
The primary risk of CVE-2020-0029 is the unauthorized disclosure of location history stored on affected devices.