PT-2020-11811 · Google · Android

Published

2020-12-15

·

Updated

2020-12-16

·

CVE-2020-0476

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-11
Description In the onNotificationRemoved function of Assistant.java, there is a possible leak of sensitive information to logs. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.
Recommendations For Android version Android-11, consider restricting log access to minimize the risk of sensitive information disclosure until a patch is available. As a temporary workaround, review and restrict the logging functionality in the Assistant.java file to prevent potential leaks of sensitive information.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-0476

Affected Products

Android