CVE-2019-2185: High severity Google Android vulnerability
In VlcDequantH263IntraBlockSH of vlcdequant.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-136173699
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2185?
CVE-2019-2185 is classified as a critical vulnerability that could allow remote code execution.
How do I fix CVE-2019-2185?
To fix CVE-2019-2185, users should update their Android devices to the latest version provided by Google.
Which versions of Android are affected by CVE-2019-2185?
CVE-2019-2185 affects Android versions 7.1.1, 7.1.2, 8.0, 8.1, 9.0, and 10.0.
What are the potential risks associated with CVE-2019-2185?
Exploitation of CVE-2019-2185 could lead to unauthorized remote code execution on the affected devices.
Does CVE-2019-2185 require user interaction for exploitation?
Yes, CVE-2019-2185 requires user interaction in order to be exploited.