PT-2020-11735 · Google · Android
Published
2020-09-01
·
Updated
2021-07-21
·
CVE-2020-0382
CVSS v3.1
2.3
Low
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android versions Android-10 through Android-11
Description
The issue is related to a possible user consent bypass due to an uncaught exception in the RunInternal of dumpstate.cpp. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not needed for exploitation.
Recommendations
For Android versions Android-10 through Android-11, consider restricting access to the dumpstate.cpp module to minimize the risk of exploitation until a patch is available. As a temporary workaround, ensure that system execution privileges are tightly controlled and monitored to prevent potential misuse.
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android