Memory Corruption Vulnerability in Android by Google
CVE-2019-2029

8.8HIGH

Key Information:

Vendor
Android
Status
Vendor
CVE Published:
19 April 2019

Summary

A vulnerability exists in the Android operating system due to a memory corruption issue caused by a use after free scenario within the btm_proc_smp_cback function of tm_ble.cc. This flaw could allow an attacker to execute arbitrary code remotely, given that the user performs a specific interaction. The impacted versions of Android include 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9, highlighting the importance of keeping devices updated to mitigate security risks.

Affected Version(s)

Android Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.