47
CVE-2020-8913
PoC —CVSS 3.1
8.8 high
EPSS
3%p86
Published
()
Modified
Description
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted application's data on the Android device. We recommend all users update Play Core to version 1.7.2 or later.
- Vendors
- android
- Products
- play core library
- Weakness
- CWE-281, CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H