Vulnerability

CVE-2024-20011

In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

9.8

Severity (Android)

N/A

Chipsets

3

Devices

10

Affected Hardware

NameAlso known asManufacturer
MT6985
Dimensity 9200
MediaTek
MT6985
Dimensity 9200+
MediaTek
MT6985W/TCZA
Dimensity 9200+
MediaTek
3 of 3 row(s) shown.

Rows per page

Page 1 of 1

Timeline

Introduced (est):
Oct 1, 2022
Reported:
Unknown
Advisory Published:
Feb 5, 2024
CVE Published:
Feb 5, 2024
Android Patch Level:
Feb 2024
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter