High severity7.8NVD Advisory· Published Sep 17, 2020· Updated Jun 17, 2026
CVE-2020-0074
CVE-2020-0074
Description
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-146204120
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
- (no CPE)range: Android-11, Android-8.0, Android-8.1, Android-9, Android-10
- Android/Androiddescription
Patches
Vulnerability mechanics
References
1- source.android.com/security/bulletin/2020-09-01nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.