PT-2023-15710 · Google · Widevine Trusted Application

Published

2023-06-26

·

Updated

2023-07-03

·

CVE-2022-48331

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Widevine Trusted Application (TA) versions 5.0.0 through 5.1.1
Description The issue is related to an integer overflow and resultant buffer overflow in the drm save keys feature, specifically with the feature name len.
Recommendations For versions 5.0.0 through 5.1.1, consider disabling the drm save keys feature until a patch is available. Restrict access to the drm save keys functionality to minimize the risk of exploitation. Avoid using the feature name len variable in the affected drm save keys feature until the issue is resolved.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-48331

Affected Products

Widevine Trusted Application