CVE-2020-0036: High severity Google Android vulnerability
In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-144679405
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Devices running Android 8.0, 8.1, 9, or 10 are identified as affected. Exploitation is local, so an attacker needs a foothold on the device rather than network-only access.
What does an attacker need to exploit it?
The vulnerability has low attack complexity and requires low privileges. No user interaction or additional execution privileges are needed.
What is the likely impact of successful exploitation?
Successful exploitation can allow access to restricted permissions and lead to local escalation of privilege. The supplied CVSS vector indicates high confidentiality, integrity, and availability impact.