Google Android Information Disclosure Vulnerability in HEIF Decoder
Vulnerability
A vulnerability allowing out-of-bounds read due to integer overflow has been identified in the HEIF decoder component of Google Android. This issue could lead to remote information disclosure without requiring additional execution privileges. Exploitation of this vulnerability does require user interaction.
Impact
Exploitation of this vulnerability could result in unauthorized access to sensitive information.
Remediation
Users can update their devices to the May 2018 security patch level to address this vulnerability.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
6.4remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
0.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
