6.9
CVSSv2

CVE-2019-2181

Published: 05/09/2019 Updated: 24/08/2020
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

In binder_transaction of binder.c in the Android kernel, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android -

Github Repositories

Capstone Created by Patrick Casey, Alex Guerriero and Connor Reardon Things TODO Stage 1 Chrome Exploit Get stage 1 exploit working on chrome browser on x86-64 linux machine (only works on the javascript shell as of now) difficulty -> easyish Compile Chrome for ARM Compile d8 for ARM and test exploit on d8 shell Get stage 1 exploit working on chrome browser on actua

Recent Articles

Too bad, so sad, exploit devs: Google patches possibly several million dollars' worth of security flaws in Android
The Register • Shaun Nichols in San Francisco • 05 Sep 2019

Except one – a 'your phone is now my phone' bug reported months ago and still not fixed Fancy buying a compact and bijou cardboard box home in a San Francisco alley? This $2.5m Android bounty will get you nearly there

Google this week emitted the September edition of its monthly Android security updates – and has left at least one known vulnerability unpatched. Also, in case you missed it, the web giant started rolling out Android 10 a few days ago. The September 2019 bundle of security fixes will be pushed out automatically to Google-branded devices, while those with other Android gear will be fed the fixes by their device manufacturer or mobile carrier. Some of the holes can be patched remotely by the ad ...