
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-0380 is a critical remote code execution vulnerability discovered in the Android System component, specifically in the allocExcessBits function of bitalloc.c. The vulnerability was disclosed in September 2020 and affects Android versions 8.0, 8.1, 9, 10, and 11. The flaw stems from an incorrect bounds check that could lead to an out-of-bounds write condition (Android Bulletin, NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The flaw is classified as CWE-787 (Out-of-bounds Write). No user interaction is required for exploitation, and no additional execution privileges are needed to exploit this vulnerability (NVD).
If successfully exploited, this vulnerability could allow a remote attacker to execute arbitrary code within the context of a privileged process. The attack can be performed remotely using a specially crafted transmission, potentially leading to complete system compromise (SecurityWeek, Threatpost).
Google addressed this vulnerability in the September 2020 Android security patch level. Users are advised to update their Android devices immediately to the security patch level 2020-09-01 or later to protect against this vulnerability. Samsung and other Android device manufacturers have also rolled out corresponding security updates to address this flaw (Bleeping Computer).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."