Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2020-0133

Description

In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145136060

POC

Reference

No PoCs from references.

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/Nivaskumark/CVE-2020-0133-packages_apps_Sett

- https://github.com/Nivaskumark/CVE-2020-0133-packages_apps_Setting

- https://github.com/Nivaskumark/CVE-2020-0133-packages_apps_Settings

- https://github.com/Nivaskumark/CVE-2020-0133-packages_apps_Settings_fix

- https://github.com/Nivaskumark/CVE-2020-0133-packages_apps_Settings_nopatch