Vulnerability

CVE-2023-32848

Component: GPU
In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896; Issue ID: ALPS08163896.

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

6.7

Severity (Android)

N/A

Chipsets

23

Devices

638

Affected Hardware

NameAlso known asManufacturer
MT6761V/WE
Helio A20
MediaTek
MT6761V/WAB
Helio A22
MediaTek
MT6761V/WBB
Helio A22
MediaTek
MT6763/6763T
Helio P23
MediaTek
MT6765
Helio P35
MediaTek
MT6771
Helio P60
MediaTek
MT6768
Helio P65
MediaTek
MT6771V/CT
Helio P70
MediaTek
MT6771V/WT
Helio P70
MediaTek
MT6779V/CU
Helio P90
MediaTek
23 of 23 row(s) shown.

Rows per page

Page 1 of 3

Timeline

Introduced (est):
Jul 1, 2017
Reported:
Unknown
Advisory Published:
Dec 4, 2023
CVE Published:
Dec 4, 2023
Android Patch Level:
Dec 2023
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter