CVE-2020-0418 describes a local escalation of privilege vulnerability in Android 10, specifically within the getPermissionInfosForGroup function of Utils.java. This logic error allows an attacker with user execution privileges to gain higher system access without requiring any user interaction. The vulnerability is rated as High severity (CVSS 7.8), indicating a low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been confirmed, its presence in a widely used operating system makes it a significant concern. Despite its severity, there is limited public exploit intelligence, with no Metasploit or ExploitDB modules available. Community discussion and media coverage are minimal, suggesting it has not garnered widespread attention, though Samsung did address it in their November 2020 updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.