![](http://www.johnjasonfallows.com/wp-content/uploads/2019/12/1-ol4nd3gijjs5cytm0ha40a.png)
In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead to local information disclosure of location data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-148180766
Published at: June 10, 2020 at 02:15PM
View on website
More Stories
New vulnerability on the NVD: CVE-2020-19107
New vulnerability on the NVD: CVE-2020-19108
New vulnerability on the NVD: CVE-2020-19109