CVE-2020-0418
HIGHAndroid 10 - Local Privilege Escalation via Utils.java getPermissionInfosForGroup Logic Error
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2020-0418. PoCs published by fernandodruszcz, Trinadh465.
AI-analyzed exploit summary This repository contains an Android Studio project demonstrating CVE-2020-0418, a vulnerability related to permission escalation in Android. The PoC includes two versions of an APK that request sensitive permissions, showcasing the exploit.
Description
In getPermissionInfosForGroup of Utils.java, there is a logic error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-153879813
Exploits (2)
This repository contains an Android Studio project demonstrating CVE-2020-0418, a vulnerability related to permission escalation in Android. The PoC includes two versions of an APK that request sensitive permissions, showcasing the exploit.
This repository contains a proof-of-concept exploit for CVE-2020-0418, a vulnerability in the Android PackageInstaller. The exploit appears to leverage a flaw in the dialog handling mechanism, potentially allowing an attacker to manipulate user interactions or bypass security prompts.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H