In showProvisioningNotification of ConnectivityService.java, there is an unsafe PendingIntent. This could lead to local information disclosure of notification data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154928507
References
| Link | Resource |
|---|---|
| https://source.android.com/security/bulletin/pixel/2020-12-01 | Patch Vendor Advisory |
Configurations
Information
Published : 2020-12-15 17:15
Updated : 2021-07-21 11:39
NVD link : CVE-2020-27041
Mitre link : CVE-2020-27041
JSON object : View
Products Affected
- android
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
