Out of Bounds Write Vulnerability in Android Products by Google
CVE-2019-2027

8.8HIGH

Key Information:

Vendor
Android
Status
Vendor
CVE Published:
19 April 2019

Summary

An out of bounds write vulnerability exists in the floor0_inverse1 function of floor0.c in Google's Android operating system. This flaw arises from insufficient checks on memory boundaries, which can be exploited to execute arbitrary code remotely. While exploiting this vulnerability necessitates user interaction, it does not require additional execution privileges. The affected versions include various Android releases, specifically 7.0 through 9. Hence, device users must remain vigilant by ensuring their systems are up to date to mitigate potential risks.

Affected Version(s)

Android Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.