Out of Bounds Write Vulnerability in Android by Google
CVE-2019-2094
7.8HIGH
Summary
A security vulnerability exists in the NuPlayerCCDecoder component of Android that could allow an out of bounds write due to missing bounds checks in the parseMPEGCCData function. This flaw may enable remote code execution if successfully exploited, which requires user interaction. The affected versions include several iterations of Android from 7.0 to 9.
Affected Version(s)
Android Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved