PT-2020-11593 · Google · Android

Published

2020-08-01

·

Updated

2024-12-24

·

CVE-2020-0238

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions 8.0 through 10
Description A logic flaw in the Settings app could lead to a confused deputy attack due to a race condition in the updatePreferenceIntents of AccountTypePreferenceLoader. This could result in local escalation of privilege and launching privileged activities with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations For Android versions 8.0 through 10, apply the fix for the issue in the AccountTypePreferenceLoader to prevent local escalation of privilege. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

ASB-A-150946634
CVE-2020-0238

Affected Products

Android