CVE-2019-20571

CRITICAL

Android - Type Confusion in WVDRM Trustlet

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. There is type confusion in the WVDRM Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14885 (September 2019).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb

Scores

CVSS v3 9.8
EPSS 0.0065
EPSS Percentile 46.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-843
Status published
Products (2)
google/android 8.0
google/android 8.1
Published Mar 24, 2020
Tracked Since Feb 18, 2026