Out of Bounds Write Vulnerability in MediaTek GPS Components
CVE-2023-20786
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 7 August 2023
Summary
An out of bounds write vulnerability has been discovered in MediaTek's GPS components, resulting from a missing bounds check. This flaw could potentially allow an attacker to escalate local privileges to system execution level without requiring any user interaction. Affected systems should be patched promptly to mitigate this risk. For more details and to obtain the patch, please refer to MediaTek's product security bulletin.
Affected Version(s)
MT2713, MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8167, MT8167S, MT8168, MT8175, MT8188, MT8195, MT8362A, MT8365, MT8673 Android 12.0, 13.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved