Out of Bound Memory Access in Sony Xperia Devices During Music Playback
CVE-2022-23747
9.8CRITICAL
What is CVE-2022-23747?
In certain Sony Xperia models, including the Xperia 1, Xperia 5, and Xperia Pro, a security vulnerability allows for out of bound memory access during music playback. This occurs due to inadequate validation of the number of frames being processed. Such vulnerabilities can potentially lead to unexpected behavior, including the possibility of arbitrary code execution as a result of manipulated audio data, posing significant risks to user data and device integrity.
Affected Version(s)
Sony Xperia series 1, 5, and Pro
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved