vendor:
Android
by:
N/A
8.8
CVSS
HIGH
RCE
119
CWE
Product Name: Android
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Android
2019
CVE-2019-2107
CVE-2019-2107 is a vulnerability that allows for remote code execution (RCE) on Android devices. The vulnerability is caused by a flaw in the HVEC (a.k.a H.265 and MPEG-H Part 2) decoder/codec, which runs under the mediacodec user. An attacker can exploit this vulnerability by crafting a malicious video with tiles enabled (ps_pps->i1_tiles_enabled_flag) and sending it to the target device. This will cause the decoder to crash, allowing the attacker to execute arbitrary code on the device.
Mitigation:
To mitigate this vulnerability, users should ensure that their devices are running the latest version of Android and that all security patches are up to date. Additionally, users should avoid downloading and opening files from untrusted sources.