Google Android Heif Decoder Out-of-Bounds Read Vulnerability Allowing Information Disclosure
Vulnerability
A vulnerability in the HEIF decoder implementation in Google Android has been identified, where improper input validation can lead to a potential out-of-bounds read. This issue could result in remote information disclosure without requiring additional execution privileges. Exploitation of this vulnerability does require user interaction.
Impact
Exploitation of this vulnerability could lead to unauthorized remote information disclosure.
Remediation
Users can update their devices to the May 2018 security patch level to address this vulnerability.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
6.4remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
0.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
