CVSSv4: NA |
CVSSv3: 7.8 |
CVSSv2: 4.6 |
VMScore: 880 |
EPSS: 0.0002 |
KEV: Not Included
Published: 14/05/2020 Updated: 21/11/2024
Vulnerability Summary
In psi_write of psi.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-148159562References: Upstream kernel
The Register • Shaun Nichols in San Francisco • 08 May 2020
Zero-click remote-code exec hole found by Googler, updates emitted
Samsung has patched a serious security hole in its smartphones that can be exploited by maliciously crafted text messages to hijack devices. It appears no user interaction is required: if Samsung's messaging app bundled with phones since 2015 receives a booby-trapped MMS, it will parse it automatically before the user even opens it. This will trigger a vulnerability in the Skia graphics library, used by the app to decode the message's embedded Qmage image. The end result is code execution on the...