Out of Bounds Write Vulnerability in Android by Google
CVE-2019-2094

7.8HIGH

Key Information:

Vendor
Android
Status
Vendor
CVE Published:
7 June 2019

Summary

A security vulnerability exists in the NuPlayerCCDecoder component of Android that could allow an out of bounds write due to missing bounds checks in the parseMPEGCCData function. This flaw may enable remote code execution if successfully exploited, which requires user interaction. The affected versions include several iterations of Android from 7.0 to 9.

Affected Version(s)

Android Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.