CVE-2019-2164 describes an out-of-bounds read vulnerability in the libxaac component of Android 10, stemming from a missing bounds check. This flaw could lead to information disclosure without requiring elevated privileges, though user interaction is necessary for successful exploitation. The vulnerability is rated as Medium severity (CVSS 6.5), with an attack vector over the network and low attack complexity, but it has a high impact on confidentiality. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The CVE has also received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.