CVE-2020-0412
NixOS vulnerability analysis and mitigation

Overview

In Android's ActivityManagerService.java, a vulnerability was identified in the setProcessMemoryTrimLevel function due to a missing permission check. The vulnerability, tracked as CVE-2020-0412, affects multiple Android versions including Android 8.0, 8.1, 9, 10, and 11. This security flaw was discovered and reported to Google with Android ID A-160390416 (CVE Details).

Technical details

The vulnerability is classified as an information disclosure flaw that exists in the Android System component. The issue stems from a missing permission check in the setProcessMemoryTrimLevel function within ActivityManagerService.java. The vulnerability requires no additional execution privileges for exploitation and can be exploited without user interaction (Android Bulletin).

Impact

The vulnerability could lead to local information disclosure of foreground processes. This means an attacker could potentially access sensitive information about currently running applications without requiring elevated privileges (Threatpost).

Exploitability

The vulnerability can be exploited locally without requiring additional execution privileges or user interaction. No evidence of active exploitation in the wild was reported at the time of disclosure (CVE Details).

Mitigation and workarounds

Google addressed this vulnerability as part of its October 2020 security update for Android. The fix was rolled out to affected Android versions 8.0, 8.1, 9, 10, and 11. Users are advised to update their devices to the latest available security patch (Android Bulletin).

Community reactions

The vulnerability was disclosed as part of Google's October 2020 security update, which addressed a total of 50 security flaws. The update included patches for various high-severity vulnerabilities across different Android components (Threatpost).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management