CVE-2019-9268

MEDIUM

Android 10 - Use-After-Free in libstagefright

Title source: llm
STIX 2.1

Description

In libstagefright, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-77474014

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0012
EPSS Percentile 1.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-416 CWE-667
Status published
Products (1)
google/android 10.0
Published Sep 27, 2019
Tracked Since Feb 18, 2026