Wednesday, June 10, 2020

New vulnerability on the NVD: CVE-2020-0121



In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead to local information disclosure of location data with User execution privileges needed. User interaction is not needed for exploitation.

from Pocket https://ift.tt/2YorR11
via IFTTT

No comments:

Post a Comment