An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and 9810 chipsets) software. A double-fetch vulnerability in Trustlet allows arbitrary TEE code execution. The Samsung ID is SVE-2019-13910 (April 2019).
The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Android | 7.0 (including) | 7.0 (including) | |
Android | 7.1.0 (including) | 7.1.0 (including) | |
Android | 7.1.1 (including) | 7.1.1 (including) | |
Android | 7.1.2 (including) | 7.1.2 (including) | |
Android | 8.0 (including) | 8.0 (including) | |
Android | 8.1 (including) | 8.1 (including) |