CVE-2020-0386: Medium severity Google Android vulnerability
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-155650356
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0386?
CVE-2020-0386 has a moderate severity rating due to its potential for local escalation of privilege.
How do I fix CVE-2020-0386?
To mitigate CVE-2020-0386, users should update their Android devices to the latest available version or security patch.
What devices are affected by CVE-2020-0386?
CVE-2020-0386 affects Google Android versions 8.0, 8.1, 9.0, 10.0, and 11.0.
Is user interaction required for CVE-2020-0386 exploitation?
Yes, user interaction is needed for an attacker to exploit CVE-2020-0386.
What type of vulnerability is CVE-2020-0386?
CVE-2020-0386 is categorized as a tapjacking vector that could allow an attacker to manipulate user privileges.