Information disclosure in Google Android - CVE-2019-20559

 

Information disclosure in Google Android - CVE-2019-20559

Published: March 24, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34643
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-20559
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Google
Affected software:
Google Android

Detailed vulnerability description

The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.

An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of photos on the lock screen. The Samsung ID is SVE-2019-15055 (October 2019).


How to mitigate CVE-2019-20559

Install update from vendor's website.

Sources