CVE-2020-0249: Medium severity Google Android vulnerability
In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-154719656
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0249?
CVE-2020-0249 has a moderate severity rating due to the potential for local information disclosure.
How do I fix CVE-2020-0249?
To mitigate CVE-2020-0249, update your Android device to the latest security patch provided by Google.
What are the affected Android versions for CVE-2020-0249?
CVE-2020-0249 affects Android versions 8.0, 8.1, 9.0, and 10.0.
Is user interaction required to exploit CVE-2020-0249?
No, user interaction is not needed for the exploitation of CVE-2020-0249.
What can be the consequences of CVE-2020-0249 exploitation?
Exploitation of CVE-2020-0249 can lead to local information disclosure, potentially compromising sensitive user data.