#VU28277 Permissions, Privileges, and Access Controls in Google Android - CVE-2020-0109
Published: May 27, 2020
Google Android
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a missing permission check in "simulatePackageSuspendBroadcast" of "NotificationManagerService.java" within the System functionality. A local user can create fake system notifications and gain elevated privileges on the target system.