CVE-2020-35551: Google Android

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allow attackers to conduct RPMB state-change attacks because an unauthorized RPMB write operation can be replayed, a related issue to CVE-2020-13799. The Samsung ID is SVE-2020-18100 (December 2020).

Affected products

  • Google Android: version 8.0 only; version 8.1 only; version 9.0 only; version 10.0 only

Published 2020-12-18. Last modified 2026-06-17.