In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.
The GNSS service improperly validates certificates (improper certificate validation, CWE-295), which allows an attacker to conduct a remote network-based attack. The vulnerability enables bypassing trust mechanisms based on certificates, resulting in obtaining elevated privileges in the system. Exploitation does not require any additional execution privileges or user interaction.
An attacker can remotely obtain privilege escalation on a vulnerable device, potentially gaining full control over it with high impact on confidentiality, integrity, and availability of the system.
Apply patches available from the manufacturer according to references — MediaTek Product Security Bulletin from July 2024 (https://corp.mediatek.com/product-security-bulletin/July-2024). Patch ID: ALPS08720039.
Devices based on Linux Foundation Yocto platforms, RDK-B (Rdkcentral), and Google Android equipped with MediaTek components — specific versions indicated in manufacturer references (MediaTek Product Security Bulletin, July 2024). Patch ID: ALPS08720039; Issue ID: MSV-1424.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGoogle Android
OSGoogle13.014.0Linuxfoundation Yocto
APPLinuxfoundation2.63.34.0Mediatek Mt2735
HWMediatekall versionsMediatek Mt2737
HWMediatekall versionsMediatek Mt6761
HWMediatekall versionsMediatek Mt6765
HWMediatekall versionsMediatek Mt6768
HWMediatekall versionsMediatek Mt6781
HWMediatekall versionsMediatek Mt6785
HWMediatekall versionsMediatek Mt6789
HWMediatekall versionsMediatek Mt6833
HWMediatekall versionsMediatek Mt6853
HWMediatekall versionsMediatek Mt6853t
HWMediatekall versionsMediatek Mt6855
HWMediatekall versionsMediatek Mt6873
HWMediatekall versionsMediatek Mt6875
HWMediatekall versionsMediatek Mt6877
HWMediatekall versionsMediatek Mt6879
HWMediatekall versionsMediatek Mt6880
HWMediatekall versionsMediatek Mt6883
HWMediatekall versionsMediatek Mt6885
HWMediatekall versionsMediatek Mt6886
HWMediatekall versionsMediatek Mt6889
HWMediatekall versionsMediatek Mt6890
HWMediatekall versionsMediatek Mt6891
HWMediatekall versionsMediatek Mt6893
HWMediatekall versionsMediatek Mt6895
HWMediatekall versionsMediatek Mt6980
HWMediatekall versionsMediatek Mt6983
HWMediatekall versionsMediatek Mt6985
HWMediatekall versions
Related vulnerabilities
Heap buffer overflow w Google Chrome na Android — sandbox escape
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...