CVE-2020-0103: Critical severity android vulnerability
Published May 4, 2020
·Updated
In a2dpaacdecodercleanup of a2dpaacdecoder.cc, there is a possible invalid free due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-148107188
Affected Software
3 affected components
Google Android=9.0
Google Android=10.0
Google Android
Remediation
Patch Available
Event History
May 4, 2020
CVE Published
via Android·12:00 AM
May 14, 2020
CVE Published
via MITRE·08:10 PM
Data Sourced
via MITRE·08:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-0103?
The severity of CVE-2020-0103 is classified as high, as it could lead to remote code execution.
2
How do I fix CVE-2020-0103?
To fix CVE-2020-0103, update your device to the latest version of Android that includes the patch.
3
Which Android versions are affected by CVE-2020-0103?
CVE-2020-0103 affects Android versions 9.0 and 10.0.
4
Can CVE-2020-0103 be exploited without user interaction?
Yes, CVE-2020-0103 can be exploited remotely without requiring user interaction.
5
What type of vulnerability is CVE-2020-0103?
CVE-2020-0103 is a memory corruption vulnerability that can lead to invalid free and remote code execution.