In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation of privilege in the TEE, with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-131252923
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/pixel/2020-09-01 | Vendor Advisory |
Configurations
Information
Published : 2020-09-17 12:15
Updated : 2020-09-23 08:29
NVD link : CVE-2020-0403
Mitre link : CVE-2020-0403
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
- android