First published: Fri Sep 27 2019(Updated: )
In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109838537
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9365 has a high severity rating as it allows for remote code execution without user interaction.
To fix CVE-2019-9365, users should update their Android devices to the latest security patch provided by Google.
CVE-2019-9365 specifically affects Android 10.
No, user interaction is not required for the exploitation of CVE-2019-9365.
CVE-2019-9365 is a deserialization error vulnerability in the Bluetooth component of Android.