CVE-2019-2106: Critical severity Google Android vulnerability
In ihevcdsaoshiftctb of ihevcdsao.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-130023983.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2106?
CVE-2019-2106 is a critical vulnerability that can lead to remote code execution due to an out of bounds write.
How do I fix CVE-2019-2106?
To mitigate CVE-2019-2106, update affected Android devices to the latest security patch provided by Google.
What versions of Android are affected by CVE-2019-2106?
CVE-2019-2106 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
Is user interaction required to exploit CVE-2019-2106?
Yes, user interaction is required for the exploitation of CVE-2019-2106.
What components of Android are involved in CVE-2019-2106?
CVE-2019-2106 involves the ihevcd_sao component within the Android OS.