CVE-2019-0622 describes an elevation of privilege vulnerability in Skype for Android, specifically affecting version 8.35. This flaw arises from the application's improper handling of certain authentication requests. With a CVSS score of 4.6 (Medium), exploitation requires physical access to the device (AV:P) and could lead to high confidentiality impact (C:H) without user interaction. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Despite limited community discussion, the vulnerability received some media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.35CPE matchmatch criteria | cpe:2.3:a:microsoft:skype:8.35:*:*:*:*:android:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.