CVE-2020-0020
MEDIUMAndroid 10 - Local Information Disclosure via ExifInterface Bounds Check
Title source: llmDescription
In getAttributeRange of ExifInterface.java, there is a possible failure to redact location information from media files due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143118731
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://source.android.com/security/bulletin/2020-02-01
Scores
CVSS v3
5.5
EPSS
0.0015
EPSS Percentile
4.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-119
Status
published
Products (1)
google/android
10.0
Published
Feb 13, 2020
Tracked Since
Feb 18, 2026