CVE-2020-0415
published 2020-10-14CVE-2020-0415: In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.17%
6.5th percentile
In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of contact data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1Android ID: A-156020795
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 10:0 < 10:2020-10-01 | 10:2020-10-01 |
| platform | frameworks_base | >= 11:0 < 11:2020-10-01 | 11:2020-10-01 |
| platform | frameworks_base | >= 8.0:0 < 8.0:2020-10-01 | 8.0:2020-10-01 |
| platform | frameworks_base | >= 8.1:0 < 8.1:2020-10-01 | 8.1:2020-10-01 |
| platform | frameworks_base | >= 9:0 < 9:2020-10-01 | 9:2020-10-01 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android up to 11.0 SystemUI information disclosure
vuldb·2026-06-21·CVSS 5.5
CVE-2020-0415 [MEDIUM] Google Android up to 11.0 SystemUI information disclosure
A vulnerability, which was classified as problematic, was found in Google Android 8.0/8.1/9.0/10.0/11.0. This vulnerability affects unknown code of the component SystemUI. Executing a manipulation can lead to information disclosure.
This vulnerability is tracked as CVE-2020-0415. The attack is restricted to local execution. No exploit exists.
A patch should be applied to remediate this issue.
GHSA
GHSA-64wm-f4x7-hw3j: In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent
ghsa_unreviewed·2022-05-24
CVE-2020-0415 [MEDIUM] CWE-276 GHSA-64wm-f4x7-hw3j: In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent
In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of contact data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1Android ID: A-156020795
OSV
CVE-2020-0415: In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent
osv·2020-10-01
CVE-2020-0415 CVE-2020-0415: In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent
In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of contact data with User execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2020-0415: Android Security Bulletin 2020-10-01
CVE: CVE-2020-0415
Severity: HIGH
Type: ID
Affected AOSP versions: 8
vendor_android·2020-10-01·CVSS 5.5
CVE-2020-0415 [MEDIUM] CVE-2020-0415: Android Security Bulletin 2020-10-01
CVE: CVE-2020-0415
Severity: HIGH
Type: ID
Affected AOSP versions: 8
Android Security Bulletin 2020-10-01
CVE: CVE-2020-0415
Severity: HIGH
Type: ID
Affected AOSP versions: 8.0, 8.1, 9, 10, 11
References: A-156020795
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-14
Published