CVE-2020-0037: High severity Google Android vulnerability
In rwi93smsetreadonly of rwi93.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143106535
Affected Software
Event History
Frequently Asked Questions
Which devices are exposed to this issue?
Devices running Android 8.0, 8.1, 9, or 10 are affected. Exploitation occurs over NFC, so exposure depends on the device being reachable through its NFC functionality.
What does an attacker need to exploit it?
The issue is remotely exploitable over NFC with no privileges and no user interaction required. The documented impact is information disclosure caused by an out-of-bounds read.
How can I identify this issue in Android security tracking?
This vulnerability is tracked as Android ID A-143106535 and CVE-2020-0037. The provided Android security bulletin and source change references correspond to the issue.