#VU28278 Permissions, Privileges, and Access Controls in Google Android - CVE-2020-0105
Published: May 27, 2020
Google Android
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a missing permission check in "onKeyguardVisibilityChanged" of "key_store_service.cpp" within the System functionality. A local user can gain elevated privileges on the target system, allowing apps to use keyguard-bound keys when the screen is locked.