CVE-2020-27030
Last modified
CVE-2020-27030 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In onCreate of HandleApiCalls.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege that allows an app to set or dismiss the alarm with no additional execution privileges needed. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
In onCreate of HandleApiCalls.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege that allows an app to set or dismiss the alarm with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150612638
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 11.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27030?
How severe is CVE-2020-27030?
How do I fix CVE-2020-27030?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-27025In EapFailureNotifier.java and SimRequiredNotifier.java, the…5.5
- CVE-2020-27026During boot, the device unlock interface behaves differently…5.5
- CVE-2020-27027In nfc_ncif_proc_get_routing of nfc_ncif.cc, there is a poss…5.5
- CVE-2020-27028In filter_incoming_event of hci_layer.cc, there is a possibl…4.4
- CVE-2020-27029In TextView of TextView.java, there is a possible app hang d…6.5
- CVE-2020-2703Vulnerability in the Oracle VM VirtualBox product of Oracle …6.5
- CVE-2020-27031In nfc_data_event of nfc_ncif.cc, there is a possible out of…4.4
- CVE-2020-27032In getRadioAccessFamily of PhoneInterfaceManager.java, there…5.5
- CVE-2020-27033In nfc_ncif_proc_get_routing of nfc_ncif.cc, there is a poss…4.4
- CVE-2020-27034In createSimSelectNotification of SimSelectNotification.java…5.5
- CVE-2020-27035In priorLinearAllocation of C2AllocatorIon.cpp, there is a p…5.5
- CVE-2020-27036In phNxpNciHal_send_ext_cmd of phNxpNciHal_ext.cc, there is …6.7
Are you affected by CVE-2020-27030?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
