PT-2020-11750 · Google · Android
Published
2020-09-01
·
Updated
2021-07-21
·
CVE-2020-0397
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android versions 8.0 through 11
Description
A permission bypass issue exists due to an unsafe PendingIntent in the getNotificationBuilder function of CarrierServiceStateTracker.java. This could lead to local information disclosure, requiring User execution privileges. No user interaction is needed for exploitation.
Recommendations
For Android versions 8.0 through 11, update to a version that includes the fix for this issue, as described in Android ID: A-155092443.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android