Learn about CVE-2020-0378, a vulnerability in Android 9, 10, and 11, potentially disclosing location data without user interaction. Find mitigation steps and patching advice.
This CVE-2020-0378 article provides detailed information about a vulnerability found in Android versions 9, 10, and 11, leading to potential information disclosure.
Understanding CVE-2020-0378
In onWnmFrameReceived of PasspointManager.java in Android, a missing permission check could result in local information disclosure of location data, requiring User execution privileges with no user interaction for exploitation.
What is CVE-2020-0378?
The vulnerability, tracked as CVE-2020-0378, allows an attacker to access location data on Android devices without the need for user interaction, potentially leading to information disclosure.
The Impact of CVE-2020-0378
The vulnerability could lead to the disclosure of sensitive location data, compromising user privacy and security on Android devices.
Technical Details of CVE-2020-0378
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates