CVE-2020-0460 is a remote information disclosure vulnerability affecting Android 11, stemming from a logic error in the CertInstaller.java component. This flaw allows for the improper installation of certificates without requiring user interaction or additional execution privileges. Rated as HIGH severity with a CVSS score of 7.5, the vulnerability has a network attack vector and low attack complexity, potentially leading to significant information disclosure. While not listed in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.