CVE-2020-0439: High severity Google Android vulnerability
In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to local escalation of privilege that allows instant apps access to permissions not allowed for instant apps, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-140256621
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0439?
CVE-2020-0439 has a high severity rating due to its potential for local escalation of privilege.
How do I fix CVE-2020-0439?
To fix CVE-2020-0439, update your Android device to the latest security patch that addresses this vulnerability.
Which Android versions are affected by CVE-2020-0439?
CVE-2020-0439 affects Android versions 8.0, 8.1, 9.0, 10.0, and 11.0.
What are the implications of CVE-2020-0439?
CVE-2020-0439 could allow instant apps to access permissions that are typically restricted for them.
Is there a workaround for CVE-2020-0439?
Currently, the best approach for CVE-2020-0439 is to apply the security updates provided by Google.