CVE-2019-2230 is a use-after-free vulnerability in the NFC component of Android 10, specifically within the nfcManager_routeAid and nfcManager_unrouteAid functions. This flaw allows for remote information disclosure without requiring user interaction or elevated privileges. With a CVSS score of 7.5 (HIGH), the vulnerability presents a significant risk of data compromise. While no public exploit code, Metasploit modules, or active exploitation have been identified, and community discussion is minimal, the potential for remote exploitation makes it a concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.