First published: Mon Nov 04 2024(Updated: )
In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =12.0 | |
Android | =12.1 | |
Android | =13.0 | |
Android | =14.0 | |
Android | =15.0 | |
https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43091 has a high severity rating due to the potential for remote code execution.
To fix CVE-2024-43091, update your Android device to the latest security patch or version provided by Google.
CVE-2024-43091 affects Google Android versions 12.0, 12.1, 13.0, 14.0, and 15.0.
CVE-2024-43091 is an out-of-bounds write vulnerability caused by an integer overflow.
No, CVE-2024-43091 can be exploited without any user interaction.