Android
cpe:2.3:o:google:android:*:*:*:*:*:*:*
A vulnerability has been identified in the Skia graphics library, specifically within the allocation function used by zlib for decompression. This issue arises from an integer overflow that can lead to an out-of-bounds write. As a result, the vulnerability could be exploited to escalate privileges locally, without requiring any additional execution rights or user interaction.
Exploitation of this vulnerability could result in unauthorized privilege escalation, allowing a user to gain elevated rights or access within the system.
Users can update their devices to the December 2024 security patch level to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.