CVE-2020-0240 is an out-of-bounds write vulnerability in the NewFixedDoubleArray function of factory.cc, affecting Android 10. This flaw, stemming from an integer overflow, could enable remote code execution without elevated privileges, though user interaction is required for exploitation. With a CVSS score of 8.8 (High), this vulnerability presents a significant risk due to its network-based attack vector and high impact on confidentiality, integrity, and availability. Despite the high severity, the attack complexity is low, making it easier to exploit once user interaction is achieved. Currently, there is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable. While there's limited community discussion and media coverage, Samsung has released updates addressing this and other critical vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.