In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing an attacker with physical possession of the device to transfer files to it over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-160691486
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published: 2020-12-15T15:53:42

Updated: 2024-08-04T06:02:51.974Z

Reserved: 2019-10-17T00:00:00

Link: CVE-2020-0473

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-12-15T16:15:13.070

Modified: 2020-12-16T18:26:06.360

Link: CVE-2020-0473

cve-icon Redhat

No data.