CVE-2020-0103: Google Android

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-148107188

Affected products

  • Google Android: version 9.0 only; version 10.0 only

Published 2020-05-14. Last modified 2026-06-17.