First published: Mon May 15 2023(Updated: )
In m4u, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07771518; Issue ID: ALPS07680084.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =12.0 | |
Google Android | =13.0 | |
Mediatek Mt6765 | ||
Mediatek Mt6768 | ||
Mediatek Mt8768 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-20722.
The severity of CVE-2023-20722 is medium with a CVSS score of 6.7.
CVE-2023-20722 affects Google Android versions 12.0 and 13.0.
CVE-2023-20722 does not affect Mediatek Mt6765, Mt6768, and Mt8768.
No, user interaction is not needed for exploitation of CVE-2023-20722.
You can patch CVE-2023-20722 by installing the patch identified as ALPS07771518.