CVE-2020-0442: Input Validation
In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote denial of service if a malicious contact file is received, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.0 Android-8.1 Android-9Android ID: A-147358092
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0442?
CVE-2020-0442 is categorized as a denial of service vulnerability which can lead to UI slowdown or crash.
How do I fix CVE-2020-0442?
To fix CVE-2020-0442, update your Android system to the latest security patch provided by Google.
Which versions of Android are affected by CVE-2020-0442?
CVE-2020-0442 affects Android versions 8.0 through 11.0.
What type of attack is CVE-2020-0442 linked to?
CVE-2020-0442 is linked to a possible denial of service attack when a malicious contact file is received.
Is user interaction needed for exploiting CVE-2020-0442?
No, user interaction is not needed for exploiting CVE-2020-0442.