CVE-2020-15165
CVE-2020-15165 is a critical-severity vulnerability in Chameleon Mini Live Debugger Project Chameleon Mini Live Debugger with a CVSS 3.x base score of 9.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-506.
Key facts
- Severity: Critical (CVSS 3.x base score 9.3)
- CVSS v2: 6.4
- EPSS exploit prediction: 1% (69th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-506
- Affected product: Chameleon Mini Live Debugger Project Chameleon Mini Live Debugger
- Published:
- Last modified:
Description
Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to v1.1.8 as soon as possible. For more information, review the referenced GitHub Security Advisory.
Frequently asked questions
- What is CVE-2020-15165?
- Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to v1.1.8 as soon as possible. For more information, review the referenced GitHub Security Advisory.
- How severe is CVE-2020-15165?
- CVE-2020-15165 has a CVSS 3.x base score of 9.3, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2020-15165 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (69th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-15165?
- CVE-2020-15165 affects Chameleon Mini Live Debugger Project Chameleon Mini Live Debugger. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-15165?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2020-15165 published?
- CVE-2020-15165 was published on 2020-08-28 and last updated on 2026-06-17.
References
- https://github.com/maxieds/ChameleonMiniLiveDebugger/security/advisories/GHSA-8q77-7hq8-f7g6
- https://play.google.com/store/apps/details?id=com.maxieds.chameleonminilivedebugger&hl=en_US
Affected products (1)
- cpe:2.3:a:chameleon_mini_live_debugger_project:chameleon_mini_live_debugger:1.1.6:*:*:*:*:android:*:*
Other CWE-506 vulnerabilities
- CVE-2026-46412 — Critical (CVSS 10.0): @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect…
- CVE-2026-28353 — Critical (CVSS 10.0): Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version…
- CVE-2024-3094 — Critical (CVSS 10.0): Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of…
- CVE-2026-77651 — Critical (CVSS 9.8): The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the…
- CVE-2026-77650 — Critical (CVSS 9.8): The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the…
- CVE-2026-77649 — Critical (CVSS 9.8): The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the…