CVE-2023-20684: Use After Free
In vdec, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07671069; Issue ID: ALPS07671069.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20684?
CVE-2023-20684 is a vulnerability in vdec that can lead to local escalation of privilege on Google Android versions 12.0 and 13.0.
How severe is CVE-2023-20684?
CVE-2023-20684 has a severity score of 6.4 (Medium).
How can CVE-2023-20684 be exploited?
CVE-2023-20684 can be exploited without user interaction.
How can I fix CVE-2023-20684?
To fix CVE-2023-20684, apply the provided patch ID: ALPS07671069 or update to a non-vulnerable version of Google Android.
Where can I find more information about CVE-2023-20684?
More information about CVE-2023-20684 can be found in the Mediatek Product Security Bulletin for April 2023: [https://corp.mediatek.com/product-security-bulletin/April-2023](https://corp.mediatek.com/product-security-bulletin/April-2023)