CVE-2019-1986 PUBLISHED CVSS 9.300000190734863 CRITICAL

In SkSwizzler::onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege in system_server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-117838472.

EPSS 0.34% · 56.7th percentile

Risk Scores

CVSS v2.0
9.300000190734863
EPSS Score
0.34%
56.7th percentile

Affected Products

VendorProductVersions
AndroidAndroidAndroid-9
googleandroid9.0

Timeline

References

Open in Interactive Console →