CVE-2020-0417: High severity Google Android vulnerability
In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.1 Android-9Android ID: A-154319182
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0417?
CVE-2020-0417 has a moderate severity level as it allows local escalation of privilege under certain conditions.
How do I fix CVE-2020-0417?
To address CVE-2020-0417, ensure that you update your Android version to the latest security patch provided by Google.
What devices are affected by CVE-2020-0417?
CVE-2020-0417 affects Android versions 8.1, 9.0, and 10.0.
Is user interaction required to exploit CVE-2020-0417?
No, user interaction is not required to exploit CVE-2020-0417.
What causes CVE-2020-0417?
CVE-2020-0417 is caused by a permissions bypass due to an empty mutable PendingIntent in the GpsNetInitiatedHandler.