CVE-2019-2108 is an out-of-bounds write vulnerability in the ihevcd_ref_list component of Android 10, affecting Google Android devices. This high-severity flaw (CVSS 7.8) requires user interaction for exploitation but could lead to remote code execution with no additional privileges. While not actively exploited (KEV: No) and lacking public exploit code (Metasploit, Nuclei, ExploitDB: None), its potential for significant impact warrants attention. Community discussion and media coverage are minimal, suggesting limited public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.