CVE-2020-0366 describes a permissions bypass vulnerability in Android's PackageInstaller, specifically affecting Android 11. This tapjacking flaw allows for local escalation of privilege if an attacker can leverage an app set as the default Assist app, requiring user interaction for successful exploitation. The vulnerability carries a CVSSv3.1 score of 7.8 (High), indicating a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. However, user interaction is a prerequisite for exploitation. Currently, there is no evidence of active exploitation (KEV: No), nor is there publicly available exploit code in common repositories like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.