CVE-2020-0074 is a local escalation of privilege vulnerability in Android's PackageManagerService.java, affecting Android versions 8.0 through 11. It allows an attacker to bypass settings and make an app the default handler for arbitrary domains. This vulnerability carries a CVSS score of 7.8 (High), requiring user execution privileges but no user interaction for exploitation, and could lead to high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog and lacking public exploit code, it has received limited community discussion and media coverage, including a fix from Samsung.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.