CVE-2020-0401: High severity Google Android vulnerability
In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and granting spurious permissions with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-150857253
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0401?
CVE-2020-0401 has a high severity level due to the potential for local escalation of privilege.
How do I fix CVE-2020-0401?
To fix CVE-2020-0401, update your Android device to the latest version provided by the manufacturer.
Which versions of Android are affected by CVE-2020-0401?
CVE-2020-0401 affects Android versions 8.0, 8.1, 9.0, and 10.0.
What exploitation risk does CVE-2020-0401 pose?
CVE-2020-0401 allows attackers to gain spurious permissions without needing additional execution privileges, leading to potential misuse.
Is user interaction required to exploit CVE-2020-0401?
No, user interaction is not needed for the exploitation of CVE-2020-0401.