First published: Tue Sep 08 2020(Updated: )
In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-146398979
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =8.0 | |
Android | =8.1 | |
Android | =9.0 | |
Android | =10.0 | |
Android | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0380 has a critical severity due to the potential for remote code execution.
To fix CVE-2020-0380, update your Android device to the latest security patch provided by Google.
CVE-2020-0380 affects Android versions 8.0, 8.1, 9.0, 10.0, and 11.0.
CVE-2020-0380 could allow attackers to perform remote code execution without user interaction.
No, user interaction is not needed for exploitation of CVE-2020-0380.