First published: Tue Dec 15 2020(Updated: )
In getGpuStatsGlobalInfo and getGpuStatsAppInfo of GpuService.cpp, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of gpu statistics with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-161903239
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27057 has a severity rating of medium due to the possible local information disclosure.
CVE-2020-27057 can be fixed by applying the latest security updates provided by the Android security bulletin.
CVE-2020-27057 can potentially disclose GPU statistics and operational information.
CVE-2020-27057 primarily affects users running Android 11.0 on their devices.
No, user interaction is not needed to exploit CVE-2020-27057.