Discover the security flaw in BlueStacks versions 4.110 and earlier for macOS, and versions 4.120 and earlier for Windows. Learn how a malicious app can exploit this vulnerability to access unauthorized system files.
A vulnerability was found in BlueStacks versions 4.110 and earlier for macOS, and versions 4.120 and earlier for Windows. BlueStacks utilizes a virtual machine (VM) running Android, allowing Android apps to be run on Windows or MacOS. The bug involves a local arbitrary file read performed through a system service call. The vulnerable method operates with System admin privilege and, when provided with a file name as a parameter, it retrieves the content of the file. Exploiting this vulnerability, a malicious app can read the content of any system file that it does not have authorization to access.
Understanding CVE-2019-14220
BlueStacks vulnerability impacting versions 4.110 and below on macOS, and versions 4.120 and below on Windows.
What is CVE-2019-14220?
This CVE identifies a security flaw in BlueStacks that allows a malicious app to read unauthorized system files through a local arbitrary file read method.
The Impact of CVE-2019-14220
Technical Details of CVE-2019-14220
BlueStacks vulnerability technical specifics.
Vulnerability Description
The bug allows unauthorized access to system files through a local arbitrary file read method in BlueStacks.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Steps to address and prevent the CVE-2019-14220 vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates