CVE-2019-1988 is an out-of-bounds write vulnerability in the SkSwizzler.cpp component of Android versions 8.0, 8.1, and 9. This flaw, identified as A-118372692, stems from improper input validation. It carries a CVSS score of 8.8 (High), indicating a critical risk. Exploitation requires user interaction but can lead to remote code execution in system_server without additional privileges, resulting in high impact to confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, there is limited community discussion, and the vulnerability is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.