Out of Bounds Write Vulnerability in Android System by Google
CVE-2019-1986

8.8HIGH

Key Information:

Vendor

Android

Status
Vendor
CVE Published:
28 February 2019

What is CVE-2019-1986?

A vulnerability exists in the Android system where an out of bounds write can occur in the SkSwizzler::onSetSampleX function of SkSwizzler.cpp. This issue arises from a lack of proper bounds checking, which may allow an attacker to escalate privileges in the system_server process without requiring additional execution rights. Exploitation of this vulnerability necessitates user interaction, making it a crucial concern for Android 9 users as it can have severe implications on device security.

Affected Version(s)

Android Android-9

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.