End of life: 4/1/2032, End of support: 4/1/2032
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ABL component, A-331966488.
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
End of life: 9/1/2031, End of support: 9/1/2031
End of life: 9/1/2031, End of support: 9/1/2031
End of life: 9/1/2031, End of support: 9/1/2031
End of life: 9/1/2031, End of support: 9/1/2031
There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional execution privileges needed.
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.
End of life: 6/1/2028, End of support: 6/1/2028
End of life: 6/1/2028, End of support: 6/1/2028
End of life: 5/1/2028, End of support: 5/1/2028
End of life: 5/1/2028, End of support: 5/1/2028
End of life: 10/1/2027, End of support: 10/1/2027
End of life: 10/1/2027, End of support: 10/1/2027
End of life: 10/1/2027, End of support: 10/1/2027
End of life: 10/1/2027, End of support: 10/1/2027
End of life: 7/1/2027, End of support: 7/1/2027
End of life: 7/1/2027, End of support: 7/1/2027
End of life: 10/1/2026, End of support: 10/1/2026
End of life: 10/1/2026, End of support: 10/1/2026
End of life: 10/1/2026, End of support: 10/1/2026
End of life: 10/1/2026, End of support: 10/1/2026
An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall number in MessageReader that is then used by sysno() and can bypass validation. This can allow the attacker to read memory from within the secure enclave. We recommend updating to Asylo 0.6.3 or past https://github.com/google/asylo/commit/90d7619e9dd99bcdb6cd28c7649d741d254d9a1a
An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended to update past 0.6.2 or git commit https://github.com/google/asylo/commit/53ed5d8fd8118ced1466e509606dd2f473707a5c
An arbitrary memory write vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to ecallrestore using the attribute output which fails to check the range of a pointer. An attacker can use this pointer to write to arbitrary memory addresses including those within the secure enclave We recommend upgrading past commit 382da2b8b09cbf928668a2445efb778f76bd9c8a
An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to encuntrustedread whose return size was not validated against the requrested size. The parameter size is unchecked allowing the attacker to read memory locations outside of the intended buffer size including memory addresses within the secure enclave. We recommend upgrading past commit b1d120a2c7d7446d2cc58d517e20a1b184b82200