Android Skia
cpe:2.3:a:google:skia:*:*:*:*:*:*:*
A heap buffer overflow vulnerability has been identified in the Skia library's BMP standard codec, specifically in the 'initializeSwizzler' function. This vulnerability allows for an out-of-bounds write, which could be exploited to escalate privileges remotely, without requiring any additional execution privileges or user interaction. The issue affects Android devices with the April 2025 security patch level.
Exploitation of this vulnerability could lead to unauthorized privilege escalation on the affected device.
Users can update their devices to the April 2025 security patch level or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.