Android Ndk Media Codec Heap Buffer Overflow Vulnerability Allowing Local Privilege Escalation

Vulnerability

A heap buffer overflow vulnerability has been identified in multiple functions of NdkMediaCodec.cpp. This vulnerability allows for an out-of-bounds write, which could lead to local escalation of privilege without requiring additional execution privileges. Exploitation of this vulnerability does not need user interaction.

Impact

Exploitation of this vulnerability could result in unauthorized access to elevated privileges, potentially allowing a user to perform actions or access resources that are normally restricted.

Remediation

Users can update to the June 2025 security patch level to address this vulnerability.

Added: Sep 4, 2025, 6:45 PM
Updated: Sep 4, 2025, 6:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.3
remediation
0.0
relevance
0.5
threat
3.2
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.