Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.
oryginał ENCVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CGoogle Android
OSGoogle≤ 5.1
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
RCE
CWE
Referencje
Powiązane podatności
CVE-2020-16010CRITICAL9.6⚠ KEVPL ✓ten sam produkt
Heap buffer overflow w Google Chrome na Android — sandbox escape
CVE-2016-1019CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
CVE-2026-76036CRITICAL9.6ten sam produkt
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to ex...
CVE-2026-19157CRITICAL9.6PL ✓ten sam produkt
Out-of-bounds write w ANGLE umożliwia sandbox escape w Chrome na Android
CVE-2026-19170CRITICAL9.6PL ✓ten sam produkt
Use-after-free w WebGL w Google Chrome na Android — możliwy sandbox escape