First published: Mon Apr 11 2022(Updated: )
In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171729; Issue ID: ALPS06171729.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =11.0 | |
Google Android | =12.0 | |
Mediatek MT6580 | ||
MediaTek MT6739 | ||
MediaTek MT6761 | ||
MediaTek MT6765 | ||
MediaTek MT6769 | ||
MediaTek MT6771 | ||
MediaTek MT6785T | ||
MediaTek MT6833 | ||
MediaTek MT6873 | ||
MediaTek MT6875T | ||
MediaTek MT6877 | ||
MediaTek MT6891 | ||
MediaTek MT8168 | ||
MediaTek MT8365 Firmware | ||
MediaTek MT8666 | ||
MediaTek MT8667 | ||
MediaTek MT8696 Firmware | ||
MediaTek MT8766Z | ||
MediaTek MT8768 | ||
MediaTek MT8788 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-20066 is classified as a moderate severity vulnerability due to its potential for local information disclosure.
To fix CVE-2022-20066, you should apply the patch identified by ALPS06171729.
CVE-2022-20066 affects Android versions 11.0 and 12.0.
No, user interaction is not needed to exploit CVE-2022-20066.
CVE-2022-20066 can lead to the leak of sensitive information due to incorrect error handling.