CVE-2025-34449
CRITICALGenymotion Scrcpy < 3.3.4 - Insecure Deserialization
Title source: ruleDescription
Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory corruption or a denial-of-service condition. This vulnerability may allow further exploitation on the host system.
Scores
CVSS v3
9.1
EPSS
0.0006
EPSS Percentile
20.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
genymotion/scrcpy
< 3.3.4
Timeline
Published
Dec 18, 2025
Tracked Since
Feb 18, 2026