CVE-2020-1895

HIGH

Instagram for Android <128.0.0.26.128 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A large heap overflow could occur in Instagram for Android when attempting to upload an image with specially crafted dimensions. This affects versions prior to 128.0.0.26.128.

Scores

CVSS v3 7.8
EPSS 0.0047
EPSS Percentile 64.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-190 CWE-680
Status published
Products (1)
facebook/instagram < 128.0.0.26.128
Published Apr 09, 2020
Tracked Since Feb 18, 2026