PT-2020-11412 · Google · Android

Published

2020-03-10

·

Updated

2021-07-21

·

CVE-2020-0047

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-10
Description A missing permission check in the setMasterMute function of AudioService.java could allow local silencing of audio without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android version Android-10, consider restricting access to the setMasterMute function until a patch is available. As a temporary workaround, review and enforce proper permission checks for audio control functions to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-0047

Affected Products

Android