cbcvebase.
CVE-2024-20011
published 2024-02-05

CVE-2024-20011: In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional…

PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.45%
36.9th percentile
In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.

Affected

4 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability resides in the ALAC (Apple Lossless Audio Codec) decoder component; monitor for anomalous media file processing or unexpected crashes/memory disclosures in alac decoder on MediaTek-based Android devices
  • No user interaction is required for exploitation, meaning a remote attacker can trigger the vulnerability without any victim action — prioritize network-facing media parsing surfaces for detection
  • Track patch status against MediaTek patch ID ALPS08441146 and Android Security Bulletin reference A-314698315 to identify unpatched devices in the environment
  • Exploitation requires no additional execution privileges, meaning successful exploitation could directly lead to remote code execution at the existing privilege level of the alac decoder process
  • ·This vulnerability is rated HIGH severity and is specific to MediaTek's ALAC decoder component on Android; scope of affected devices is limited to MediaTek chipset-based Android devices addressed in the February 2024 Android Security Bulletin
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.