Out-of-Bound Write Vulnerability in Android by Google
CVE-2019-2035
7.8HIGH
Summary
An out-of-bound write vulnerability exists in the rw_i93_sm_update_ndef function of the rw_i93.cc file in Android. This flaw is due to the lack of a proper bounds check, which can potentially allow attackers to escalate privileges locally. Successful exploitation requires user interaction, making it crucial for users to remain vigilant about application permissions and their security settings.
Affected Version(s)
Android Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved