CVE-2020-0227: High severity Google Android vulnerability
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-129476618
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0227?
CVE-2020-0227 is classified as a high severity vulnerability due to its potential for local escalation of privilege.
How do I fix CVE-2020-0227?
To fix CVE-2020-0227, update affected Android devices to the latest available version that includes the security patch addressing this vulnerability.
What versions of Android are affected by CVE-2020-0227?
CVE-2020-0227 affects Android versions 8.0, 8.1, 9.0, and 10.0.
What type of vulnerability is CVE-2020-0227?
CVE-2020-0227 is a permissions bypass vulnerability that allows potential local escalation of privilege.
How can CVE-2020-0227 impact users?
CVE-2020-0227 can lead to unauthorized background data usage or the ability to launch activities from the background without user interaction.