Vulnerabilities > CVE-2019-9468 - Double Free vulnerability in Google Android 10.0/11.0/20200601

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
google
CWE-415

Summary

In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-139683471

Vulnerable Configurations

Part Description Count
OS
Google
3

Common Weakness Enumeration (CWE)