CVE-2019-2118 is a local information disclosure vulnerability affecting Android versions 8.0, 8.1, and 9. It stems from uninitialized or partially initialized stack variables in the Parcel.cpp file. This medium-severity flaw (CVSS 5.5) requires no user interaction or additional privileges for exploitation, potentially leading to the disclosure of sensitive local information. There is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable. Community discussion and media coverage are minimal, with only one article mentioning the vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.