CVE-2019-9262

HIGH

Android 10 - Remote Code Execution via Integer Overflow in MPEG4Extractor

Title source: llm
STIX 2.1

Description

In MPEG4Extractor, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111792351

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0073
EPSS Percentile 49.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-190 CWE-787
Status published
Products (1)
google/android 10.0
Published Sep 27, 2019
Tracked Since Feb 18, 2026