Description
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. Type confusion in the MLDAP Trustlet allows arbitrary code execution. The Samsung ID is SVE-2020-16599 (April 2020).
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb
Third Party Advisory x_refsource_misc
https://www.tuttoandroid.net/samsung/samsung-patch-sicurezza-aprile-2020-798658/
Scores
CVSS v3
9.8
EPSS
0.0022
EPSS Percentile
44.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-843
Status
published
Products (2)
google/android
9.0
google/android
10.0
Published
Apr 08, 2020
Tracked Since
Feb 18, 2026