Out-of-bounds Read Vulnerability in Redex by Facebook
CVE-2022-36938
9.8CRITICAL
What is CVE-2022-36938?
The DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 is susceptible to an out-of-bounds read when it processes the string index table. This vulnerability can be exploited by attackers through specially crafted third-party Android APK files, potentially allowing them to execute arbitrary code remotely. This represents a significant security risk, as it could compromise the integrity of the application and lead to unauthorized access or control.
Affected Version(s)
Redex < 3b44c64
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved