{"api_version":"1","generated_at":"2026-07-23T13:40:08+00:00","cve":"CVE-2020-0258","urls":{"html":"https://cve.report/CVE-2020-0258","api":"https://cve.report/api/cve/CVE-2020-0258.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-0258","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-0258"},"summary":{"title":"CVE-2020-0258","description":"In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure in the application that is started next with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-157598956","state":"PUBLIC","assigner":"security@android.com","published_at":"2020-08-11 20:15:00","updated_at":"2022-05-03 13:00:00"},"problem_types":["CWE-459"],"metrics":[],"references":[{"url":"http://packetstormsecurity.com/files/158869/Android-App-Zygotes-Improper-Guarding.html","name":"http://packetstormsecurity.com/files/158869/Android-App-Zygotes-Improper-Guarding.html","refsource":"MISC","tags":[],"title":"Android App Zygotes Improper Guarding ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://source.android.com/security/bulletin/2020-08-01","name":"https://source.android.com/security/bulletin/2020-08-01","refsource":"MISC","tags":["Vendor Advisory"],"title":"Android Security Bulletin—August 2020  |  Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-0258","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-0258","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"258","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"258","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-0258","ASSIGNER":"security@android.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Android","version":{"version_data":[{"version_value":"Android-10"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information disclosure"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://source.android.com/security/bulletin/2020-08-01","url":"https://source.android.com/security/bulletin/2020-08-01"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/158869/Android-App-Zygotes-Improper-Guarding.html","url":"http://packetstormsecurity.com/files/158869/Android-App-Zygotes-Improper-Guarding.html"}]},"description":{"description_data":[{"lang":"eng","value":"In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure in the application that is started next with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-157598956"}]}},"nvd":{"publishedDate":"2020-08-11 20:15:00","lastModifiedDate":"2022-05-03 13:00:00","problem_types":["CWE-459"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.9},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"258","Ordinal":"158323","Title":"CVE-2020-0258","CVE":"CVE-2020-0258","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"258","Ordinal":"1","NoteData":"In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure in the application that is started next with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-157598956","Type":"Description","Title":null},{"CveYear":"2020","CveId":"258","Ordinal":"2","NoteData":"2020-08-11","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"258","Ordinal":"3","NoteData":"2020-08-14","Type":"Other","Title":"Modified"}]}}}