CVE-2025-34449

CRITICAL

Genymotion Scrcpy < 3.3.4 - Insecure Deserialization

Title source: rule

Description

Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory corruption or a denial-of-service condition. This vulnerability may allow further exploitation on the host system.

Scores

CVSS v3 9.1
EPSS 0.0006
EPSS Percentile 20.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

genymotion/scrcpy < 3.3.4

Timeline

Published Dec 18, 2025
Tracked Since Feb 18, 2026