CVE-2019-9306 describes an out-of-bounds write vulnerability in the libMpegTPDec component of Android 10, stemming from an integer overflow. This high-severity flaw (CVSS 8.8) allows for potential remote code execution without elevated privileges, though user interaction is required for successful exploitation. While no public exploits, Metasploit modules, or KEV entries exist, and community discussion is minimal, the vulnerability poses a significant risk due to its potential for complete compromise of confidentiality, integrity, and availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.