First published: Tue Nov 08 2022(Updated: )
In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06382421; Issue ID: ALPS06382421.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =10.0 | |
Google Android | =11.0 | |
Google Android | =12.0 | |
Mediatek Mt6771 | ||
Mediatek Mt6779 | ||
Mediatek Mt6785 | ||
Mediatek Mt6853 | ||
Mediatek Mt6853t | ||
Mediatek Mt6873 | ||
Mediatek Mt6877 | ||
Mediatek Mt6885 | ||
Mediatek Mt6891 | ||
Mediatek Mt6893 | ||
Mediatek Mt8168 | ||
Mediatek Mt8175 | ||
Mediatek Mt8183 | ||
Mediatek Mt8365 | ||
Mediatek Mt8385 | ||
Mediatek Mt8788 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-21778.
The severity of CVE-2022-21778 is medium with a CVSS score of 6.7.
The affected software includes Google Android versions 10.0, 11.0, and 12.0.
No, user interaction is not needed for exploitation of CVE-2022-21778.
To fix CVE-2022-21778, apply the patch with Patch ID ALPS06382421.