CVE-2020-0225: Critical severity Google Android vulnerability
In a2dpvendorldacdecoderdecodepacket of a2dpvendorldacdecoder.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142546668
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0225?
CVE-2020-0225 is rated as a critical vulnerability that could allow remote code execution without additional privileges.
How do I fix CVE-2020-0225?
To fix CVE-2020-0225, users should update their Android device to the latest security patch that addresses this vulnerability.
Which versions of Android are affected by CVE-2020-0225?
CVE-2020-0225 affects Android 10.0 and potentially earlier versions depending on the specific device implementation.
What type of attack can exploit CVE-2020-0225?
CVE-2020-0225 can be exploited through remote code execution attacks by leveraging the out of bounds write vulnerability.
Is user interaction required to exploit CVE-2020-0225?
No, user interaction is not needed for an attacker to exploit CVE-2020-0225.