04 February 20, 19:59
(This post was last modified: 04 February 20, 19:59 by silversurfer.)
Quote:Android Security Bulletin — February 2020
Published February 3, 2020
The Android Security Bulletin contains details of security vulnerabilities affecting Android devices. Security patch levels of 2020-02-05 or later address all of these issues. To learn how to check a device's security patch level, see Check and update your Android version.
Android partners are notified of all issues at least a month before publication. Source code patches for these issues will be released to the Android Open Source Project (AOSP) repository in the next 48 hours. We will revise this bulletin with the AOSP links when they are available.
The most severe of these issues is a critical security vulnerability in the System component that could enable a remote attacker using a specially crafted transmission to execute arbitrary code within the context of a privileged process. The severity assessment is based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed.
Refer to the Android and Google Play Protect mitigations section for details on the Android security platform protections and Google Play Protect, which improve the security of the Android platform.
Note: Information on the latest over-the-air update (OTA) and firmware images for Google devices is available in the February 2020 Pixel Update Bulletin.
Read more: https://source.android.com/security/bulletin/2020-02-01