CVE-2020-0007

MEDIUM

Android 8.0-10 - Local Information Disclosure via Uninitialized Heap Memory in Sensor.cpp

Title source: llm
STIX 2.1

Description

In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-141890807

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://source.android.com/security/bulletin/2020-01-01

Scores

CVSS v3 5.5
EPSS 0.0017
EPSS Percentile 6.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-908
Status published
Products (4)
google/android 8.0
google/android 8.1
google/android 9.0
google/android 10.0
Published Jan 08, 2020
Tracked Since Feb 18, 2026