CVE-2020-0386
published 2020-09-17CVE-2020-0386: In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of…
PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
0.39%
31.1th percentile
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-155650356
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_apps_settings | >= 10:0 < 10:2020-09-01 | 10:2020-09-01 |
| platform | packages_apps_settings | >= 8.0:0 < 8.0:2020-09-01 | 8.0:2020-09-01 |
| platform | packages_apps_settings | >= 8.1:0 < 8.1:2020-09-01 | 8.1:2020-09-01 |
| platform | packages_apps_settings | >= 9:0 < 9:2020-09-01 | 9:2020-09-01 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2020-0386: Android Security Bulletin 2020-09-01
CVE: CVE-2020-0386
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
vendor_android·2020-09-01·CVSS 5.5
CVE-2020-0386 [MEDIUM] CVE-2020-0386: Android Security Bulletin 2020-09-01
CVE: CVE-2020-0386
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
Android Security Bulletin 2020-09-01
CVE: CVE-2020-0386
Severity: HIGH
Type: EoP
Affected AOSP versions: 8.0, 8.1, 9, 10
References: A-155650356
GHSA
GHSA-j9v4-qqch-4wvq: In onCreate of RequestPermissionActivity
ghsa_unreviewed·2022-05-24
CVE-2020-0386 [MEDIUM] CWE-269 GHSA-j9v4-qqch-4wvq: In onCreate of RequestPermissionActivity
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-155650356
OSV
CVE-2020-0386: In onCreate of RequestPermissionActivity
osv·2020-09-01
CVE-2020-0386 CVE-2020-0386: In onCreate of RequestPermissionActivity
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges needed. User interaction is needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-09-17
Published