CVE-2020-0138: Critical severity android vulnerability
In getelementattrrsp of btifrc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if bluetoothtbd were used, which it isn't in typical Android platforms, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142878416
Affected Software
Remediation
Event History
Frequently Asked Questions
Are typical Android platforms exposed to remote code execution through this issue?
The described remote code execution path requires bluetoothtbd to be used. It is not used on typical Android platforms, so that path is not typically exposed.
Does exploitation require user interaction or prior execution privileges?
No. The vulnerability is remotely exploitable with low attack complexity, requires no privileges, and does not require user interaction.
Which Android version is identified as affected?
The provided information identifies Android 10 as affected.
What remediation is available?
A patch is available. The referenced Android security bulletin is dated June 1, 2020.