Race Condition Vulnerability in Mediatek's ion Component
CVE-2022-20110
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 3 May 2022
Summary
A race condition in Mediatek's ion component may allow an attacker to exploit a use after free vulnerability, potentially leading to local privilege escalation. This vulnerability can be exploited without user interaction, providing an opportunity for unauthorized access to system-level privileges. Immediate patches are recommended to mitigate this risk.
Affected Version(s)
MT6580, MT6735, MT6737, MT6739, MT6750, MT6750S, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6797, MT6833, MT6853, MT6853T, MT6873, MT6875, MT6877, MT6883, MT6885, MT6889, MT6893, MT8167, MT8168, MT8173, MT8185, MT8321, MT8362A, MT8365, MT8385, MT8666, MT8675, MT8695, MT8696, MT8765, MT8766, MT8768, MT8786, MT8788, MT8789, MT8791, MT8797 Android 9.0, 10.0, 11.0, 12.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved