CVE-2019-2196

MEDIUM

Android -8.0, -8.1, -9, -10 - SQL Injection

Title source: llm
STIX 2.1

Description

In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135269143

Exploits (1)

nomisec WORKING POC 2 stars
by IOActive · poc
https://github.com/IOActive/AOSP-DownloadProviderDbDumperSQLiLimit

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0069
EPSS Percentile 71.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-89
Status published
Products (4)
google/android 8.0
google/android 8.1
google/android 9.0
google/android 10.0
Published Nov 13, 2019
Tracked Since Feb 18, 2026