#VU25358 Information disclosure in Google Android - CVE-2020-0023
Published: February 14, 2020
Google Android
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists within the System functionality of Android due to a missing permission check in "setPhonebookAccessPermission" of "AdapterService.java". A remote attacker can gain unauthorized access to sensitive information if a malicious app enables contacts over Bluetooth.