In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local escalation of privilege to change contact data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150857116
                
            References
                    | Link | Resource | 
|---|---|
| https://source.android.com/security/bulletin/pixel/2020-12-01 | Patch Vendor Advisory | 
| https://source.android.com/security/bulletin/pixel/2020-12-01 | Patch Vendor Advisory | 
Configurations
                    History
                    21 Nov 2024, 04:53
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://source.android.com/security/bulletin/pixel/2020-12-01 - Patch, Vendor Advisory | 
Information
                Published : 2020-12-15 16:15
Updated : 2024-11-21 04:53
NVD link : CVE-2020-0486
Mitre link : CVE-2020-0486
CVE.ORG link : CVE-2020-0486
JSON object : View
Products Affected
                - android
CWE
                
                    
                        
                        CWE-276
                        
            Incorrect Default Permissions
