Vulnerability

CVE-2023-20726

Component: POSITION
In mnld, there is a possible leak of GPS location due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07735968 / ALPS07884552 (For MT6880, MT6890, MT6980, MT6980D and MT6990 only); Issue ID: ALPS07735968 / ALPS07884552 (For MT6880, MT6890, MT6980, MT6980D and MT6990 only).

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

3.3

Severity (Android)

N/A

Chipsets

100

Devices

1657

Affected Hardware

NameAlso known asManufacturer
MT6580
MediaTek
MT6739
MediaTek
MT6761V/WE
Helio A20
MediaTek
MT6761V/WAB
Helio A22
MediaTek
MT6761V/WBB
Helio A22
MediaTek
MT6762V/WB
Helio A25
MediaTek
MT6762V/WD
Helio A25
MediaTek
MT6762
Helio P22
MediaTek
MT6765
Helio P35
MediaTek
MT6771
Helio P60
MediaTek
100 of 100 row(s) shown.

Rows per page

Page 1 of 10

Timeline

Introduced (est):
Jan 1, 2015
Reported:
Unknown
Advisory Published:
May 5, 2023
CVE Published:
May 15, 2023
Android Patch Level:
May 2023
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter