CVE-2019-9385 is an out-of-bounds read vulnerability in the libxaac library affecting Android 10, stemming from a missing bounds check. This medium-severity flaw (CVSS 6.5) allows for remote information disclosure with high confidentiality impact, requiring user interaction for exploitation. While no public exploits, Metasploit modules, or community discussions are reported, its presence in Android 10 necessitates patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.