CVE-2019-2052: High severity Google Android vulnerability
In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.1 Android-9 Android ID: A-117556606
Affected Software
Event History
Frequently Asked Questions
Which Android releases are identified as affected?
The affected versions listed are Android 7.0, 7.1.1, 7.1.2, 8.1, and 9.
Does exploiting this issue require authentication, elevated privileges, or user interaction?
No. The CVSS vector indicates the flaw is remotely exploitable with low attack complexity, requires no privileges, and requires no user interaction.
What is the expected impact if exploitation succeeds?
The stated impact is remote information disclosure caused by an out-of-bounds read resulting from type confusion. The CVSS vector indicates high confidentiality impact, with no integrity or availability impact.