VYPR
Critical severity9.8NVD Advisory· Published Jun 11, 2020· Updated Jun 17, 2026

CVE-2020-0138

CVE-2020-0138

Description

In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if bluetoothtbd were used, which it isn't in typical Android platforms, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142878416

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Google/Android2 versions
    cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*
    • (no CPE)range: Android-10
  • Android/Androiddescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.