CVE-2020-0391
HIGHAndroid - Local Privilege Escalation via Unenforced Protected Broadcast
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-0391. PoCs published by nanopathi.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2020-0391, targeting Android's autofill framework. The code demonstrates how an attacker could manipulate autofill services to trigger unintended behavior, potentially leading to information disclosure or privilege escalation.
Description
In applyPolicy of PackageManagerService.java, there is possible arbitrary command execution as System due to an unenforced protected-broadcast. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-158570769
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2020-0391, targeting Android's autofill framework. The code demonstrates how an attacker could manipulate autofill services to trigger unintended behavior, potentially leading to information disclosure or privilege escalation.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H