PT-2020-11584 · Google · Android
Published
2020-07-01
·
Updated
2022-07-12
·
CVE-2020-0227
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions 8.0 through 10
Description
A permissions bypass issue exists due to a missing permission check in the
onCommand method of CompanionDeviceManagerService.java. This could lead to local escalation of privilege, allowing background data usage or launching from the background without requiring additional execution privileges. User interaction is not needed for exploitation.Recommendations
For Android versions 8.0 through 10, consider restricting background data usage and launching from the background as a temporary mitigation measure until a patch is available.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android