CVE-2019-6740 is a critical heap-based buffer overflow vulnerability affecting Samsung Galaxy S9 devices running firmware prior to the January 2019 Security Update. This flaw resides in the ASN.1 parser, where improper length validation of user-supplied data can lead to arbitrary code execution. With a CVSS score of 8.8 (High), exploitation requires user interaction, typically by visiting a malicious page or opening a crafted file. While there are no known public exploits or Metasploit modules, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2019-01CPE matchmatch criteria | cpe:2.3:o:samsung:galaxy_s9_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.