CVE-2019-2227

MEDIUM

Android <10 - Info Disclosure

Title source: llm
STIX 2.1

Description

In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-140768453

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://source.android.com/security/bulletin/2019-12-01

Scores

CVSS v3 6.5
EPSS 0.0044
EPSS Percentile 63.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-125
Status published
Products (2)
google/android 9.0
google/android 10.0
Published Dec 06, 2019
Tracked Since Feb 18, 2026