PT-2020-11377 · Google · Android

Published

2020-01-08

·

Updated

2022-01-01

·

CVE-2020-0008

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-8.0 through Android-10
Description A race condition in the LowEnergyClient::MtuChangedCallback function of low energy client.cc can cause an out of bounds read, potentially leading to local information disclosure. This issue does not require additional execution privileges or user interaction to be exploited.
Recommendations For Android versions Android-8.0 through Android-10, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Out of bounds Read

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-0008

Affected Products

Android