PT-2020-11721 · Google · Android

Published

2020-12-15

·

Updated

2022-08-06

·

CVE-2020-0368

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-11
Description The issue is related to a possible permission bypass due to improper input validation in the queryInternal function of CallLogProvider.java. This could lead to local information disclosure of voicemail metadata, requiring User execution privileges. No user interaction is needed for exploitation.
Recommendations For Android version Android-11, consider restricting access to the queryInternal function of CallLogProvider.java to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and improve input validation in the queryInternal function to prevent permission bypass.

Fix

RCE

Weakness Enumeration

Related Identifiers

ASB-A-143230980
CVE-2020-0368

Affected Products

Android