First published: Tue Mar 24 2020(Updated: )
An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and 9810 chipsets) software. A double-fetch vulnerability in Trustlet allows arbitrary TEE code execution. The Samsung ID is SVE-2019-13910 (April 2019).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =7.0 | |
Google Android | =7.1.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Google Android | =8.0 | |
Google Android | =8.1 | |
Samsung Exynos 7570 | ||
Samsung Exynos 7870 | ||
Samsung Exynos 7880 | ||
Samsung Exynos 7885 | ||
Samsung Exynos 8890 | ||
Samsung Exynos 8895 | ||
Samsung Exynos 9810 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-20610.
This vulnerability affects Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and 9810 chipsets) software.
The severity level of CVE-2019-20610 is critical (8.1).
This vulnerability is a double-fetch vulnerability in Trustlet that allows arbitrary TEE code execution.
To fix this vulnerability, apply the security update provided by Samsung. More information can be found at the following reference: [https://security.samsungmobile.com/securityUpdate.smsb](https://security.samsungmobile.com/securityUpdate.smsb)