First published: Tue Dec 15 2020(Updated: )
In AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a non-system app to send a broadcast it shouldn't have permissions to send, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157472962
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-0481.
The severity of CVE-2020-0481 is low with a CVSS score of 3.3.
CVE-2020-0481 allows a non-system app to send a broadcast it shouldn't have permissions to send, potentially leading to a local escalation of privilege.
No, user interaction is not needed for exploitation of CVE-2020-0481.
You can learn more about CVE-2020-0481 on the Android Security Bulletin for December 2020.