VYPR
Unrated severityNVD Advisory· Published Mar 24, 2020· Updated Aug 4, 2024

CVE-2020-10849

CVE-2020-10849

Description

Samsung mobile devices with Exynos7885/8895/9810 chipsets running Android 8-10 have a Gatekeeper trustlet flaw enabling brute-force of screen lock password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Samsung mobile devices with Exynos7885/8895/9810 chipsets running Android 8-10 have a Gatekeeper trustlet flaw enabling brute-force of screen lock password.

Vulnerability

An issue exists in the Gatekeeper trustlet on Samsung mobile devices with Exynos7885, Exynos8895, and Exynos9810 chipsets running Android O(8.x), P(9.0), and Q(10.0). The trustlet does not enforce rate limiting or lockout mechanisms, allowing an unlimited number of password attempts. This vulnerability is identified by Samsung ID SVE-2019-14575 and was disclosed in January 2020 [1].

Exploitation

An attacker with physical access to the device can repeatedly attempt screen lock passwords without triggering any lockout or delay. No authentication or special privileges are required beyond physical possession. The attacker can systematically brute-force the password until the correct one is found.

Impact

Successful exploitation reveals the screen lock password, granting the attacker full access to the device and all user data. The attacker gains the same privileges as the legitimate user, leading to complete compromise of confidentiality and integrity.

Mitigation

Samsung released a security update in January 2020 as part of its monthly maintenance release. Users should apply the latest firmware update via Samsung's security update process. No workaround is available; updating to the patched version is the only mitigation [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.