First published: Mon Mar 04 2024(Updated: )
In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08522504; Issue ID: ALPS08522504.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
All of | ||
Google Android | =13.0 | |
Any of | ||
MediaTek MT2713 | ||
MediaTek MT2715 | ||
MediaTek MT8173 | ||
MediaTek MT8188 | ||
MediaTek MT8195Z | ||
MediaTek MT8390 | ||
MediaTek MT8395 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-20020 has a severity level that indicates it could lead to local information disclosure with system execution privileges required.
To fix CVE-2024-20020, apply the patch identified by ALPS08522504.
CVE-2024-20020 is an out of bounds write vulnerability caused by an incorrect bounds check.
CVE-2024-20020 affects Google Android version 13.0 and possibly other systems using OPTEE.
No, user interaction is not needed for exploitation of CVE-2024-20020.