Vulnerabilities > CVE-2020-0103 - Release of Invalid Pointer or Reference vulnerability in Google Android 10.0/9.0

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
google
CWE-763
critical

Summary

In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-148107188

Vulnerable Configurations

Part Description Count
OS
Google
2

Common Weakness Enumeration (CWE)