CVE-2020-0073 is a critical out-of-bounds write vulnerability in the Android operating system, specifically within the rw_t2t_handle_tlv_detect_rsp function of rw_t2t_ndef.cc. This flaw affects Android versions 8.0, 8.1, 9, and 10. It carries a CVSS score of 9.8 (Critical) due to its potential for remote code execution over NFC without requiring user interaction or additional privileges. While the EPSS score is low, indicating a low probability of exploitation in the wild, the FAUCET Risk Score is high at 82/100. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, but it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.