Google Android Trusty Out-of-Bounds Read Vulnerability Allowing Information Disclosure

Vulnerability

A vulnerability in the Trusty component of Google Android has been identified, where an out-of-bounds read may occur due to an improper bounds check in the 'dev_send' function of 'tipc_dev_ql'. This flaw could lead to local information disclosure without requiring additional execution privileges or user interaction for exploitation.

Impact

Exploitation of this vulnerability could result in unauthorized local information disclosure.

Remediation

Users can update their devices to the March 2025 security patch level to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9