CVE-2020-0303

HIGH

Android 11 - Use-After-Free in Media Extractor

Title source: llm
STIX 2.1

Description

In the Media extractor, there is a possible use after free due to improper locking. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148223229

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0056
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-416 CWE-667
Status published
Products (1)
google/android 11.0
Published Sep 17, 2020
Tracked Since Feb 18, 2026