Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2020-0188

Description

In onCreatePermissionRequest of SettingsSliceProvider.java, there is a possible permissions bypass due to a PendingIntent error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147355897

POC

Reference

No PoCs from references.

Github

- https://github.com/Nivaskumark/packages_apps_Settings_CVE-2020-0188_A10_R33

- https://github.com/Nivaskumark/packages_apps_settings_A10_r33_CVE-2020-0188

- https://github.com/Satheesh575555/packages_apps_Settings_AOSP10_r33_CVE-2020-0188

- https://github.com/ShaikUsaf/ShaikUsaf-packages_apps_settings_AOSP10_r33_CVE-2020-0188

- https://github.com/Trinadh465/packages_apps_Settings_AOSP10_r33_CVE-2020-0188_CVE-0219

- https://github.com/Trinadh465/packages_apps_Settings_AOSP10_r33_CVE-2020-0219_CVE-2020-0188_old

- https://github.com/Trinadh465/packages_apps_Settings_AOSP10_r33_CVE-2020-0219_CVE-2020-0188_old-one

- https://github.com/nomi-sec/PoC-in-GitHub