CVE-2020-0468
published 2020-12-14CVE-2020-0468: In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permission check…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.14%
4.0th percentile
In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-158484422
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 10:0 < 10:2020-12-01 | 10:2020-12-01 |
| platform | frameworks_base | >= 11:0 < 11:2020-12-01 | 11:2020-12-01 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2020-0468: Android Security Bulletin 2020-12-01
CVE: CVE-2020-0468
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11
References: A-158484422
vendor_android·2020-12-01·CVSS 5.5
CVE-2020-0468 [MEDIUM] CVE-2020-0468: Android Security Bulletin 2020-12-01
CVE: CVE-2020-0468
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11
References: A-158484422
Android Security Bulletin 2020-12-01
CVE: CVE-2020-0468
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11
References: A-158484422
GHSA
GHSA-pmq5-vgh2-fjq5: In listen() and related functions of TelephonyRegistry
ghsa_unreviewed·2022-05-24
CVE-2020-0468 [MEDIUM] CWE-276 GHSA-pmq5-vgh2-fjq5: In listen() and related functions of TelephonyRegistry
In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-158484422
OSV
CVE-2020-0468: In listen() and related functions of TelephonyRegistry
osv·2020-12-01
CVE-2020-0468 CVE-2020-0468: In listen() and related functions of TelephonyRegistry
In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-14
Published