Permissions, Privileges, and Access Controls in Google Android - CVE-2020-0015
Published: February 14, 2020
Google Android
Detailed vulnerability description
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists within the Framework functionality of Android due to a possible way to overlay the Certificate Installation dialog by a malicious application in "onCreate" of "CertInstaller.java". A local attacker can gain elevated privileges on the target system.