Vulnerability

CVE-2022-20092

In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366061; Issue ID: ALPS06366061.

Impact

Severity (Manufact.)

MEDIUM

Severity (NIST)

5.5

Severity (Android)

N/A

Chipsets

53

Devices

602

Affected Hardware

NameAlso known asManufacturer
MT6761V/WE
Helio A20
MediaTek
MT6761V/WAB
Helio A22
MediaTek
MT6761V/WBB
Helio A22
MediaTek
MT6768
Helio P65
MediaTek
MT6779V/CU
Helio P90
MediaTek
MT6779V/CV
Helio P95
MediaTek
MT6785V/CD
Helio G90
MediaTek
MT6785V/CC
Helio G90T
MediaTek
MT6833
Dimensity 6020
Dimensity 700
MediaTek
MT6833V/ZA
Dimensity 6020
Dimensity 700
MediaTek
53 of 53 row(s) shown.

Rows per page

Page 1 of 6

Timeline

Introduced (est):
Apr 1, 2018
Reported:
Unknown
Advisory Published:
May 3, 2022
CVE Published:
May 3, 2022
Android Patch Level:
None
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter