CVE-2019-9262 is an out-of-bounds write vulnerability in the MPEG4Extractor component of Android, specifically affecting Android 10. This flaw, caused by an integer overflow, could enable remote code execution within the media extractor without requiring elevated privileges. Rated with a CVSS score of 8.8 (High), exploitation necessitates user interaction, typically involving a malicious media file. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not in CISA's KEV catalog, there has been limited community discussion and media coverage, including a mention by CISA regarding ICS advisories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.