CVE-2020-0453

MEDIUM

Google Android - Information Disclosure

Title source: rule

Description

In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-8.0 Android-8.1Android ID: A-159060474

Exploits (4)

gitlab WRITEUP
by nanopathi · poc
https://gitlab.com/nanopathi/Packages_apps_Nfc_CVE-2020-0453
nomisec WORKING POC
by Trinadh465 · poc
https://github.com/Trinadh465/packages_apps_Nfc_AOSP10_r33_CVE-2020-0453
nomisec WORKING POC
by nanopathi · poc
https://github.com/nanopathi/Packages_apps_Nfc_CVE-2020-0453
nomisec WORKING POC
by pazhanivel07 · poc
https://github.com/pazhanivel07/Nfc_CVE-2020-0453

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 9.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (3)
google/android 8.0
google/android 8.1
google/android 9.0
Published Nov 10, 2020
Tracked Since Feb 18, 2026