Where
-Infinity
0
EOL
Apr 1, 2032
Support Ends
Apr 1, 2032

End of life: 4/1/2032, End of support: 4/1/2032

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ABL component, A-331966488.

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.

First published (updated )
EOL
Sep 1, 2031
Support Ends
Sep 1, 2031

End of life: 9/1/2031, End of support: 9/1/2031

First published (updated )
EOL
Sep 1, 2031
Support Ends
Sep 1, 2031

End of life: 9/1/2031, End of support: 9/1/2031

First published (updated )
EOL
Sep 1, 2031
Support Ends
Sep 1, 2031

End of life: 9/1/2031, End of support: 9/1/2031

First published (updated )
EOL
Sep 1, 2031
Support Ends
Sep 1, 2031

End of life: 9/1/2031, End of support: 9/1/2031

First published (updated )
Severity
8.4
Infoleak
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional execution privileges needed.

First published (updated )
Severity
5.3
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.

First published (updated )
EOL
Jun 1, 2028
Support Ends
Jun 1, 2028

End of life: 6/1/2028, End of support: 6/1/2028

First published (updated )
EOL
Jun 1, 2028
Support Ends
Jun 1, 2028

End of life: 6/1/2028, End of support: 6/1/2028

First published (updated )
EOL
May 1, 2028
Support Ends
May 1, 2028

End of life: 5/1/2028, End of support: 5/1/2028

First published (updated )
EOL
May 1, 2028
Support Ends
May 1, 2028

End of life: 5/1/2028, End of support: 5/1/2028

First published (updated )
EOL
Oct 1, 2027
Support Ends
Oct 1, 2027

End of life: 10/1/2027, End of support: 10/1/2027

First published (updated )
EOL
Oct 1, 2027
Support Ends
Oct 1, 2027

End of life: 10/1/2027, End of support: 10/1/2027

First published (updated )
EOL
Oct 1, 2027
Support Ends
Oct 1, 2027

End of life: 10/1/2027, End of support: 10/1/2027

First published (updated )
EOL
Oct 1, 2027
Support Ends
Oct 1, 2027

End of life: 10/1/2027, End of support: 10/1/2027

First published (updated )
EOL
Jul 1, 2027
Support Ends
Jul 1, 2027

End of life: 7/1/2027, End of support: 7/1/2027

First published (updated )
EOL
Jul 1, 2027
Support Ends
Jul 1, 2027

End of life: 7/1/2027, End of support: 7/1/2027

First published (updated )
EOL
Oct 1, 2026
Support Ends
Oct 1, 2026

End of life: 10/1/2026, End of support: 10/1/2026

First published (updated )
EOL
Oct 1, 2026
Support Ends
Oct 1, 2026

End of life: 10/1/2026, End of support: 10/1/2026

First published (updated )
EOL
Oct 1, 2026
Support Ends
Oct 1, 2026

End of life: 10/1/2026, End of support: 10/1/2026

First published (updated )
EOL
Oct 1, 2026
Support Ends
Oct 1, 2026

End of life: 10/1/2026, End of support: 10/1/2026

First published (updated )
Severity
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall number in MessageReader that is then used by sysno() and can bypass validation. This can allow the attacker to read memory from within the secure enclave. We recommend updating to Asylo 0.6.3 or past https://github.com/google/asylo/commit/90d7619e9dd99bcdb6cd28c7649d741d254d9a1a

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended to update past 0.6.2 or git commit https://github.com/google/asylo/commit/53ed5d8fd8118ced1466e509606dd2f473707a5c

First published (updated )
Severity
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

An arbitrary memory write vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to ecallrestore using the attribute output which fails to check the range of a pointer. An attacker can use this pointer to write to arbitrary memory addresses including those within the secure enclave We recommend upgrading past commit 382da2b8b09cbf928668a2445efb778f76bd9c8a

Remedy

We recommend upgrading past commit 382da2b8b09cbf928668a2445efb778f76bd9c8a
First published (updated )
Severity
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to encuntrustedread whose return size was not validated against the requrested size. The parameter size is unchecked allowing the attacker to read memory locations outside of the intended buffer size including memory addresses within the secure enclave. We recommend upgrading past commit b1d120a2c7d7446d2cc58d517e20a1b184b82200

Remedy

We recommend upgrading past commit b1d120a2c7d7446d2cc58d517e20a1b184b82200
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203