
Cloud Vulnerability DB
A community-led vulnerabilities database
StrandHogg 2.0 (CVE-2020-0096) is a critical escalation of privilege vulnerability discovered in Android's startActivities component of ActivityStartController.java. The vulnerability was disclosed to Google on December 4, 2019, and was subsequently patched in May 2020. It affects all Android versions below Android 10 and allows attackers to hijack apps on the victim's device without requiring root access or specific permissions (SecurityWeek, HelpNet Security).
The vulnerability exploits Android's multitasking system through a different method than its predecessor StrandHogg 1.0. Unlike the original StrandHogg that used taskAffinity, StrandHogg 2.0 uses a code-based execution method that leaves no markers, making it more difficult to detect. The vulnerability allows attackers to target multiple apps simultaneously, whereas the original version could only target one app at a time. The attack doesn't require any specific permissions or root access to execute (HelpNet Security).
When successfully exploited, StrandHogg 2.0 enables attackers to hijack nearly any application on the target device, insert malicious overlays, steal login credentials, access private files, read SMS messages, track device location, record phone calls, and access the device's camera and microphone. The vulnerability can affect multiple apps simultaneously, making it particularly dangerous for user privacy and data security (SecurityWeek).
While the vulnerability is considered critical, there have been no reported cases of active exploitation in the wild. However, security researchers warn that attackers could potentially use both StrandHogg and StrandHogg 2.0 vulnerabilities together to maximize their attack surface. The vulnerability affects approximately 90% of Android devices, specifically those running versions below Android 10 (SecurityWeek).
Google released a patch for the vulnerability in the May 2020 Android security updates for Android versions 8.0, 8.1, and 9. Users are advised to update their devices to the latest firmware as soon as possible. App developers should implement security measures by setting all public activities to launchMode="singleTask" or launchMode="singleInstance" in AndroidManifest.xml. Users should also be vigilant about permission pop-ups that don't contain an app name and be wary of apps requesting login credentials for already authenticated sessions (HelpNet Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."