PT-2020-11584 · Google · Android

Published

2020-07-01

·

Updated

2022-07-12

·

CVE-2020-0227

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions 8.0 through 10
Description A permissions bypass issue exists due to a missing permission check in the onCommand method of CompanionDeviceManagerService.java. This could lead to local escalation of privilege, allowing background data usage or launching from the background without requiring additional execution privileges. User interaction is not needed for exploitation.
Recommendations For Android versions 8.0 through 10, consider restricting background data usage and launching from the background as a temporary mitigation measure until a patch is available.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-129476618
CVE-2020-0227

Affected Products

Android