#VU25387 Race condition in Google Android - CVE-2020-0030
Published: February 17, 2020
Google Android
Description
The vulnerability allows a local attacker to escalate privileges on the system.
The
vulnerability exists within the "Binder driver" component of Android due to a race condition in "binder_thread_release"
of "binder.c". A local attacker can use a specially crafted file to exploit the race, trigger a use-after-free error and execute arbitrary code with elevated privileges on the target system.