CVE-2024-43091: Integer Overflow
Published Nov 4, 2024
·Updated
In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
6 affected components
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android=14.0
Google Android=15.0
Google Android
Remediation
Patch Available
Event History
Nov 4, 2024
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 13, 2024
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43091?
CVE-2024-43091 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2024-43091?
To fix CVE-2024-43091, update your Android device to the latest security patch or version provided by Google.
3
Which versions of Android are affected by CVE-2024-43091?
CVE-2024-43091 affects Google Android versions 12.0, 12.1, 13.0, 14.0, and 15.0.
4
What kind of vulnerability is CVE-2024-43091?
CVE-2024-43091 is an out-of-bounds write vulnerability caused by an integer overflow.
5
Does CVE-2024-43091 require user interaction for exploitation?
No, CVE-2024-43091 can be exploited without any user interaction.