CVE-2019-20607: Critical severity android vulnerability
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (MSM8996, MSM8998, Exynos7420, Exynos7870, Exynos8890, and Exynos8895 chipsets) software. A heap overflow in the keymaster Trustlet allows attackers to write to TEE memory, and achieve arbitrary code execution. The Samsung ID is SVE-2019-14126 (May 2019).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-20607.
Which devices are affected by this vulnerability?
Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software, specifically those with MSM8996, MSM8998, Exynos7420, Exynos7870, Exynos8890, and Exynos8895 chipsets, are affected.
What is the severity of CVE-2019-20607?
CVE-2019-20607 has a severity rating of 9.8, which is considered critical.
How does this vulnerability allow arbitrary code execution?
This vulnerability allows attackers to achieve arbitrary code execution through a heap overflow in the keymaster Trustlet, which allows them to write to TEE (Trusted Execution Environment) memory.
How can I fix CVE-2019-20607?
To fix CVE-2019-20607, it is recommended to apply the security update provided by Samsung. Please refer to the official Samsung security update page for more information.