CVE-2019-1987: Critical severity Google Android vulnerability
Published Feb 4, 2019
·Updated
In onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-118143775.
Affected Software
7 affected components
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android
Remediation
Patch Available
Event History
Feb 4, 2019
CVE Published
via Android·12:00 AM
Feb 28, 2019
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-1987?
CVE-2019-1987 has a high severity level due to its potential for remote code execution.
2
How do I fix CVE-2019-1987?
Updating your Android device to the latest security patch will resolve CVE-2019-1987.
3
Which Android versions are affected by CVE-2019-1987?
CVE-2019-1987 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
4
Is user interaction required to exploit CVE-2019-1987?
Yes, user interaction is necessary for exploiting CVE-2019-1987.
5
What type of vulnerability is CVE-2019-1987?
CVE-2019-1987 is an out of bounds write vulnerability.