Vulnerabilities > CVE-2019-2095 - Use After Free vulnerability in Google Android 9.0

047910
CVSS 7.6 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
high complexity
google
CWE-416

Summary

In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-124232283.

Vulnerable Configurations

Part Description Count
OS
Google
1

Common Weakness Enumeration (CWE)