CVE-2019-20589

CRITICAL

Samsung Android O(8.x) and P(9.0) - Arbitrary Code Execution via SKPM Trustlet Type Confusion

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the SKPM Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14892 (August 2019).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb

Scores

CVSS v3 9.8
EPSS 0.0086
EPSS Percentile 53.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-843
Status published
Products (3)
google/android 8.0
google/android 8.1
google/android 9.0
Published Mar 24, 2020
Tracked Since Feb 18, 2026