CVE-2020-0226
In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in...
- Published
- Jul 17, 2020
- Updated
- Aug 4, 2024
- Assigning CNA
- google_android
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 19.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150226994
Sources
2Exploit for CVE-2020-0226 targeting Android 10 native frameworks. Provides a proof-of-concept for a critical elevation-of-privilege vulnerability in the Android media server component.
- frameworks_native_CVE-2020-0226Research
Analyzes and demonstrates Android native framework vulnerability CVE-2020-0226, providing binary analysis and exploitation insights.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.