Field Assessment
AI analysis pending.
Exhibit — Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Detected Signals
exploit remote code execution code execution
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2019-2108
Severity
HIGH
CVSS
7.8
EPSS
1.04%
Android
Original Filing — NVD Description
In ihevcd_ref_list of ihevcd_ref_list.c in Android 10, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.