In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing an attacker with physical possession of the device to transfer files to it over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-160691486
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: google_android

Published: 2020-12-15T15:53:42

Updated: 2020-12-15T15:53:42

Reserved: 2019-10-17T00:00:00


Link: CVE-2020-0473

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-12-15T16:15:13.070

Modified: 2020-12-16T18:26:06.360


Link: CVE-2020-0473

JSON object: View

cve-icon Redhat Information

No data.

CWE