Out-of-Bound Read Vulnerability in Android by Google
CVE-2019-2039

5MEDIUM

Key Information:

Vendor
Android
Status
Vendor
CVE Published:
19 April 2019

Summary

An out-of-bounds read vulnerability exists in the rw_i93_sm_detect_ndef function of rw_i93.cc within Android platforms. This issue is due to a failure to properly perform bounds checks, which may result in local information disclosure. Exploitation of this vulnerability requires user interaction, allowing attackers to gain unauthorized access to sensitive data without needing elevated privileges.

Affected Version(s)

Android Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.