Improper Privilege Management in Google Android - CVE-2020-0403
Published: September 17, 2020 / Updated: September 24, 2020
Google Android
Description
The vulnerability allows a local privileged user to execute arbitrary code.
In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation of privilege in the TEE, with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-131252923