Missing Authorization in Google Android - CVE-2020-0375
Published: September 17, 2020 / Updated: September 22, 2020
Google Android
Description
The vulnerability allows a local authenticated user to execute arbitrary code.
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege and the setting of supported EUICC countries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253476