Android
cpe:2.3:o:samsung:android:*:*:*:*:*:*:*
- >= 12, < 15
A vulnerability allowing out-of-bounds read has been identified in the libsthmbc.so library, prior to the SMR January 2025 Release 1. This vulnerability arises from improper handling of malformed video thumbnail bitstreams, which can lead to local attackers reading arbitrary memory. Exploitation of this vulnerability requires user interaction.
Exploitation of this vulnerability allows local attackers to read arbitrary memory, potentially leading to information disclosure or further exploitation.
Users can apply the January 2025 Security Maintenance Release, which includes the necessary patch for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.