CVE-2019-2115

HIGH

Android <9 - Memory Corruption

Title source: llm

Description

In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 8.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415 CWE-787
Status published

Affected Products (5)

google/android
google/android
google/android
google/android
google/android

Timeline

Published Sep 05, 2019
Tracked Since Feb 18, 2026