CVE-2019-2004

MEDIUM

Android 7.0-9 - Local Information Disclosure via Uninitialized Data in InputTransport.cpp

Title source: llm
STIX 2.1

Description

In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-115739809

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0017
EPSS Percentile 6.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-908
Status published
Products (6)
google/android 7.0
google/android 7.1.1
google/android 7.1.2
google/android 8.0
google/android 8.1
google/android 9.0
Published Jun 19, 2019
Tracked Since Feb 18, 2026