CVE-2020-0439
HIGHAndroid 8.0-11 - Unauthenticated Permissions Bypass via PackageManagerService
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-0439. PoCs published by Satheesh575555.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2020-0439, targeting Android's autofill framework. The code demonstrates performance tests that manipulate autofill behavior, potentially leading to privilege escalation or information leakage.
Description
In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to local escalation of privilege that allows instant apps access to permissions not allowed for instant apps, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-140256621
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2020-0439, targeting Android's autofill framework. The code demonstrates performance tests that manipulate autofill behavior, potentially leading to privilege escalation or information leakage.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H