CVE-2023-21282

HIGH

Android - Out-of-bounds Write in TRANSPOSER_SETTINGS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2023-21282. PoCs published by Trinadh465.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2023-21282, targeting a vulnerability in the Fraunhofer FDK AAC Codec Library for Android. The exploit appears to focus on memory corruption or buffer overflow issues within the AAC decoder components.

Description

In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

Exploits (2)

nomisec WORKING POC
by Trinadh465 · poc
https://github.com/Trinadh465/external_aac_android-4.2.2_r1_CVE-2023-21282

This repository contains a proof-of-concept exploit for CVE-2023-21282, targeting a vulnerability in the Fraunhofer FDK AAC Codec Library for Android. The exploit appears to focus on memory corruption or buffer overflow issues within the AAC decoder components.

Classification
Working Poc 80%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Fraunhofer FDK AAC Codec Library for Android (version 4.2.2_r1)
No auth needed
Prerequisites: Access to a vulnerable Android device or emulator running the affected AAC codec library
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Trinadh465 · poc
https://github.com/Trinadh465/external_aac_AOSP10_r33_CVE-2023-21282

This repository contains a proof-of-concept exploit for CVE-2023-21282, targeting a vulnerability in the Fraunhofer FDK AAC Codec Library for Android. The exploit appears to focus on memory corruption or buffer overflow issues within the AAC decoder components.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Fraunhofer FDK AAC Codec Library for Android (AOSP10_r33)
No auth needed
Prerequisites: Access to a vulnerable version of the FDK AAC Codec Library · Ability to deliver a maliciously crafted AAC file to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0103
EPSS Percentile 59.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (4)
google/android 11.0
google/android 12.0
google/android 12.1
google/android 13.0
Published Aug 14, 2023
Tracked Since Feb 18, 2026