First published: Mon Nov 02 2020(Updated: )
In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to local escalation of privilege that allows instant apps access to permissions not allowed for instant apps, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-140256621
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =8.0 | |
Android | =8.1 | |
Android | =9.0 | |
Android | =10.0 | |
Android | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0439 has a high severity rating due to its potential for local escalation of privilege.
To fix CVE-2020-0439, update your Android device to the latest security patch that addresses this vulnerability.
CVE-2020-0439 affects Android versions 8.0, 8.1, 9.0, 10.0, and 11.0.
CVE-2020-0439 could allow instant apps to access permissions that are typically restricted for them.
Currently, the best approach for CVE-2020-0439 is to apply the security updates provided by Google.