CVE-2020-0271

HIGH

Android 11 - Local Privilege Escalation and Tapjacking via Insecure Default Setting

Title source: llm
STIX 2.1

Description

In the Settings app, there is an insecure default value. This could lead to local escalation of privilege and tapjacking with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144507081

References (1)

Core 1
Core References

Scores

CVSS v3 7.3
EPSS 0.0016
EPSS Percentile 5.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-1188
Status published
Products (1)
google/android 11.0
Published Sep 18, 2020
Tracked Since Feb 18, 2026