CVE-2023-20951: Critical severity android vulnerability
In gattprocessprepwritersp of gattcl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-258652631
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2023-20951?
CVE-2023-20951 can lead to remote code execution if exploited, without requiring additional execution privileges.
Which versions of Android are affected by CVE-2023-20951?
CVE-2023-20951 affects Android versions 11.0, 12.0, 12.1, and 13.0.
Is user interaction necessary to exploit CVE-2023-20951?
No, user interaction is not needed for the exploitation of CVE-2023-20951.
How do I mitigate the risks associated with CVE-2023-20951?
To mitigate CVE-2023-20951, ensure your Android device is updated with the latest security patches provided by Google.
What kind of vulnerability is CVE-2023-20951 classified as?
CVE-2023-20951 is classified as an out-of-bounds write vulnerability.