Out of Bounds Write Vulnerability in MediaTek GPS Components
CVE-2023-20786
6.7MEDIUM
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 7 August 2023
What is CVE-2023-20786?
An out of bounds write vulnerability has been discovered in MediaTek's GPS components, resulting from a missing bounds check. This flaw could potentially allow an attacker to escalate local privileges to system execution level without requiring any user interaction. Affected systems should be patched promptly to mitigate this risk. For more details and to obtain the patch, please refer to MediaTek's product security bulletin.
Affected Version(s)
MT2713, MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8167, MT8167S, MT8168, MT8175, MT8188, MT8195, MT8362A, MT8365, MT8673 Android 12.0, 13.0