CVE-2019-2205: Use After Free
In ProxyResolverV8::SetPacScript of proxyresolverv8.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139806216
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2205?
CVE-2019-2205 is classified as a high severity vulnerability due to its potential for remote code execution.
How does CVE-2019-2205 affect Android devices?
CVE-2019-2205 can potentially lead to memory corruption on Android devices, affecting versions 8.0, 8.1, 9.0, and 10.0.
How do I fix CVE-2019-2205?
To mitigate CVE-2019-2205, users should update their Android devices to the latest security patches provided by Google.
What could be the consequence of exploiting CVE-2019-2205?
Exploitation of CVE-2019-2205 may allow an attacker to execute arbitrary code on the affected device without requiring user interaction.
Is user interaction required to exploit CVE-2019-2205?
No, user interaction is not needed for the exploitation of CVE-2019-2205.