CVE-2020-0103: Google Android
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-148107188
Affected products
- Google Android: version 9.0 only; version 10.0 only
Published 2020-05-14. Last modified 2026-06-17.