CVE-2020-0418: High severity Google Android vulnerability
Published Nov 2, 2020
·Updated
In getPermissionInfosForGroup of Utils.java, there is a logic error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-153879813
Affected Software
2 affected components
Google Android=10.0
Google Android
Remediation
Patch Available
Event History
Nov 2, 2020
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 10, 2020
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs local execution with User privileges on an affected Android 10 device. No user interaction is required once that level of execution is obtained.
2
What is the potential impact?
Successful exploitation can allow local escalation of privilege and can affect confidentiality, integrity, and availability.
3
Is a fix available?
Yes. A patch is available for this issue.