Security Advisory

CVE-2020-8913

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-08-12 07:10:12
Last updated 2024-08-04 10:12:10
Assigner Google
State PUBLISHED

Description

A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Androids Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted applications data on the Android device. We recommend all users update Play Core to version 1.7.2 or later.