Global Buffer Overflow Vulnerability in Genymobile Scrcpy
CVE-2025-34449
Key Information:
- Vendor
Genymobile
- Status
- Vendor
- CVE Published:
- 18 December 2025
Badges
What is CVE-2025-34449?
A vulnerability exists in Genymobile's scrcpy, where versions up to 3.3.3 are susceptible to a global buffer overflow triggered by the sc_read32be function. This occurs during the processing of specially crafted device messages via the sc_device_msg_deserialize() and process_msgs() functions. Successful exploitation may result in memory corruption or application crashes. Depending on the specific execution environment, it may also open avenues for further exploitation.
Affected Version(s)
scrcpy 0 <= 3.3.3
scrcpy commit 3e40b24
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
