
Cloud Vulnerability DB
A community-led vulnerabilities database
In Android Auto Settings, there was a possible permission bypass vulnerability (CVE-2020-0265) due to an unsafe PendingIntent. This vulnerability was disclosed in September 2020 and affected Android devices running Android 11 (CISA Bulletin).
The vulnerability exists in Android Auto Settings where an unsafe PendingIntent implementation could lead to a permission bypass. The vulnerability received a CVSS score of 2.1, indicating relatively low severity (CISA Bulletin).
The vulnerability could allow attackers to bypass certain permission restrictions within Android Auto Settings, potentially gaining unauthorized access to protected functionality.
The vulnerability requires local access to the device for exploitation. No evidence of active exploitation in the wild has been reported.
Google addressed this vulnerability in the Android 11 security update. Users should ensure their devices are updated to the latest available version that includes the security patch (Android Security Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."