CVE-2020-0162

MEDIUM

Android 10 - Denial of Service via MPEG4Extractor.cpp parseSampleAuxiliaryInformationOffsets

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-0162. PoCs published by Pazhanivelmani.

AI-analyzed exploit summary This repository contains source code files from the Android Open Source Project (AOSP) camera module, specifically related to CVE-2020-0162. The code includes implementations of camera functionality but does not contain an exploit or proof-of-concept. It appears to be a snapshot of vulnerable code for analysis purposes.

Description

In parseSampleAuxiliaryInformationOffsets of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-124526959

Exploits (1)

nomisec WRITEUP
by Pazhanivelmani · poc
https://github.com/Pazhanivelmani/av_CVE-2020-0162_A10r33

This repository contains source code files from the Android Open Source Project (AOSP) camera module, specifically related to CVE-2020-0162. The code includes implementations of camera functionality but does not contain an exploit or proof-of-concept. It appears to be a snapshot of vulnerable code for analysis purposes.

Classification
Writeup 90%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: Android Open Source Project (AOSP) camera module
No auth needed
Prerequisites: Access to vulnerable Android device · Understanding of AOSP camera module
devstral-2 · analyzed Apr 30, 2026 Full analysis →

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://source.android.com/security/bulletin/pixel/2020-06-01

Scores

CVSS v3 6.5
EPSS 0.0063
EPSS Percentile 45.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (1)
google/android 10.0
Published Jun 11, 2020
Tracked Since Feb 18, 2026