CVE-2020-0227
HIGHAndroid 8.0-10 - Unauthenticated Permissions Bypass in CompanionDeviceManagerService
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-0227. PoCs published by nanopathi.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2020-0227, targeting Android's autofill framework. The code demonstrates how an attacker could exploit the vulnerability to manipulate autofill behavior, potentially leading to unauthorized data access or manipulation.
Description
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-129476618
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2020-0227, targeting Android's autofill framework. The code demonstrates how an attacker could exploit the vulnerability to manipulate autofill behavior, potentially leading to unauthorized data access or manipulation.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H