Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-2205. PoCs published by aemmitt-ns.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2019-2205, leveraging memory corruption via crafted PAC file URLs to achieve arbitrary code execution on Android devices. The exploit manipulates Proxy Auto-Config (PAC) file resolution to trigger controlled memory operations.
Description
In ProxyResolverV8::SetPacScript of proxy_resolver_v8.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139806216
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2019-2205, leveraging memory corruption via crafted PAC file URLs to achieve arbitrary code execution on Android devices. The exploit manipulates Proxy Auto-Config (PAC) file resolution to trigger controlled memory operations.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H