
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-0107 is a high-severity information disclosure vulnerability discovered in Android 10's PhoneInterfaceManager.java component, specifically in the getUiccCardsInfo function. The vulnerability was identified in October 2019 and was officially addressed in the July 2020 Android security updates. The flaw affects Android 10 devices and stems from improper input validation (Android Bulletin, SecurityWeek).
The vulnerability exists in the getUiccCardsInfo function of PhoneInterfaceManager.java due to improper input validation. This security flaw was tracked under Android ID A-146570216. The issue was addressed as part of the 2020-07-01 security patch level (Android Bulletin).
The vulnerability could lead to local information disclosure on affected devices. The exploitation does not require additional execution privileges or user interaction, making it a significant security concern for Android 10 users (Android Bulletin).
The vulnerability can be exploited locally without requiring additional execution privileges or user interaction. No evidence of active exploitation in the wild has been publicly reported (Android Bulletin).
Google addressed this vulnerability in the July 2020 Android security updates. Users should ensure their devices are updated to the 2020-07-01 security patch level or newer to protect against this vulnerability (SecurityWeek).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."