In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue ID: MSV-2599.
2025-03-03T03:15:09.293
2025-04-22T13:47:27.490
Analyzed
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | android | 14.0 | Yes | |
Operating System | android | 15.0 | Yes | |
Hardware | mediatek | mt6765 | - | No |
Hardware | mediatek | mt6768 | - | No |
Hardware | mediatek | mt6833 | - | No |
Hardware | mediatek | mt6835 | - | No |
Hardware | mediatek | mt6853 | - | No |
Hardware | mediatek | mt6855 | - | No |
Hardware | mediatek | mt6879 | - | No |
Hardware | mediatek | mt6886 | - | No |
Hardware | mediatek | mt6893 | - | No |
Hardware | mediatek | mt6897 | - | No |
Hardware | mediatek | mt6983 | - | No |
Hardware | mediatek | mt6985 | - | No |
Hardware | mediatek | mt6989 | - | No |
Hardware | mediatek | mt8796 | - | No |