Integer Overflow Vulnerability in Chrome OS by Imagination Technologies
CVE-2019-16508

7.8HIGH

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
1 October 2019

Summary

The vulnerability in the Imagination Technologies driver for Chrome OS enables attackers to exploit an integer overflow issue. This can lead to privilege escalation through a malicious application, due to unintentional access granted to the GPU process for /dev/dri/card1 and the PowerVR ioctl handler. The flaw was identified in certain versions of Chrome OS, making it vital for users to ensure their systems are updated to the latest releases to mitigate this risk.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.