PT-2019-16008 · Google · Android

Published

2019-02-28

·

Updated

2021-07-21

·

CVE-2019-1992

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions 7.0 through 9
Description A possible use-after-free issue due to a race condition exists in the bta hl sdp query results function of bta hl main.cc. This could lead to remote code execution with no additional execution privileges needed. User interaction is required for exploitation.
Recommendations For Android versions 7.0 through 9, update to a version that contains a fix for this issue.

Fix

Race Condition

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1992

Affected Products

Android