PT-2020-11562 · Google · Android
Published
2020-06-11
·
Updated
2020-06-15
·
CVE-2020-0204
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions Android-10
Description
The issue is related to a Time of Check/Time of Use condition in the InstallPackage function of package.cpp, which could allow a bypass of the signature check for an OS update. This might lead to local escalation of privilege, enabling the bypass of the initial zip file signature check without requiring additional execution privileges. User interaction is necessary for exploitation.
Recommendations
For Android version Android-10, update to a version that includes a fix for this issue to prevent potential local escalation of privilege.
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android