First published: Mon Feb 04 2019(Updated: )
In SkSwizzler::onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege in system_server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-117838472.
Credit: security@android.com security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1986 is categorized as a high-severity vulnerability due to potential remote escalation of privileges.
To fix CVE-2019-1986, ensure that your Android device is updated to the latest security patch that addresses this vulnerability.
CVE-2019-1986 affects Android version 9.0 and potentially other versions that utilize the Skia graphics library.
CVE-2019-1986 is an out-of-bounds write vulnerability that can lead to privilege escalation.
Yes, user interaction is necessary for the exploitation of CVE-2019-1986.