CVE-2020-0418
In getPermissionInfosForGroup of Utils.java, there is a logic error. This could lead to local escalation of privilege with User execution privileges needed....
- Published
- Nov 10, 2020
- Updated
- Aug 4, 2024
- Assigning CNA
- google_android
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 19.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
In getPermissionInfosForGroup of Utils.java, there is a logic error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-153879813
Sources
2- CVE-2020-0418Exploit
Android APK exploit generator for CVE-2020-0418, producing two APK variants via AndroidManifest.xml modifications to demonstrate the vulnerability.
Android PackageInstaller source code with patch for CVE-2020-0418, a local privilege escalation vulnerability. Provides patched AOSP10 code for security research and analysis.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.