Out-of-Bound Read Vulnerability in Android Products by Google
CVE-2019-2040

5MEDIUM

Key Information:

Vendor
Android
Status
Vendor
CVE Published:
19 April 2019

Summary

A vulnerability in Android allows for a potential out-of-bounds read due to a lack of proper bounds checking in the rw_i93_process_ext_sys_info function. This flaw could enable local information disclosure, requiring user interaction for exploitation. The affected version is Android-9, and it is important to ensure that devices are kept up-to-date with security patches.

Affected Version(s)

Android Android-9

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.