PT-2020-11791 · Google · Android

Published

2020-11-01

·

Updated

2021-07-21

·

CVE-2020-0449

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions Android-8.0 through Android-11
Description In the btm sec disconnected function of btm sec.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution in the Bluetooth server with no additional execution privileges needed. User interaction is needed for exploitation.
Recommendations For Android versions Android-8.0 through Android-11, update to a version that includes the fix for the memory corruption issue in btm sec disconnected of btm sec.cc. As a temporary workaround, consider disabling Bluetooth functionality until a patch is available.

Fix

Memory Corruption

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-162497143
CVE-2020-0449

Affected Products

Android