CVE-2020-0382: Low severity Google Android vulnerability
Published Sep 8, 2020
·Updated
In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exception. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-152944488
Affected Software
3 affected components
Google Android=10.0
Google Android=11.0
Google Android
Event History
Sep 8, 2020
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 17, 2020
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-0382?
CVE-2020-0382 is considered a high-severity vulnerability due to its potential for local information disclosure.
2
How do I fix CVE-2020-0382?
To mitigate CVE-2020-0382, you should update your Android device to version 11.0 or later.
3
Which versions of Android are affected by CVE-2020-0382?
CVE-2020-0382 affects Android versions 10.0 and 11.0.
4
Is user interaction required to exploit CVE-2020-0382?
No, user interaction is not needed for the exploitation of CVE-2020-0382.
5
What type of data could be disclosed due to CVE-2020-0382?
CVE-2020-0382 could lead to local information disclosure of bug report data.