Description
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-129476618
Exploits (1)
nomisec
WORKING POC
by nanopathi · poc
https://github.com/nanopathi/framework_base_AOSP10_r33_CVE-2020-0227
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://source.android.com/security/bulletin/2020-07-01
Scores
CVSS v3
7.8
EPSS
0.0001
EPSS Percentile
1.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-862
Status
published
Products (4)
google/android
8.0
google/android
8.1
google/android
9.0
google/android
10.0
Published
Jul 17, 2020
Tracked Since
Feb 18, 2026