PT-2020-11397 · Google · Android

Published

2020-03-10

·

Updated

2020-03-11

·

CVE-2020-0029

CVSS v3.1

2.3

Low

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-10
Description The issue concerns the storage of location history in the WifiConfigManager, which can only be deleted by performing a factory reset. This could lead to local information disclosure, requiring System execution privileges for exploitation. No user interaction is needed for exploitation.
Recommendations For Android version Android-10, consider performing a factory reset to delete the stored location history as a mitigation measure. As a temporary workaround, restrict access to sensitive location data to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-0029

Affected Products

Android