CVE-2020-0242: Use After Free
In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-151643722
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0242?
CVE-2020-0242 is classified as a critical vulnerability due to its potential for local escalation of privilege.
How do I fix CVE-2020-0242?
To mitigate CVE-2020-0242, update your Android device to the latest version provided by Google, as this issue has been addressed in subsequent updates.
What causes CVE-2020-0242?
CVE-2020-0242 is caused by a use-after-free vulnerability in the NuPlayerDriver due to improper locking mechanisms.
Which Android versions are affected by CVE-2020-0242?
CVE-2020-0242 affects Google Android versions 8.0, 8.1, 9.0, and 10.0.
Is user interaction required to exploit CVE-2020-0242?
No, user interaction is not needed for the exploitation of CVE-2020-0242.