Learn about CVE-2019-2135 affecting Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9. Understand the out-of-bounds read vulnerability leading to local information disclosure.
Android devices are impacted by a vulnerability in the Mfc_Transceive function, potentially leading to information disclosure without additional privileges.
Understanding CVE-2019-2135
This CVE affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9, allowing for out-of-bounds read and local information disclosure.
What is CVE-2019-2135?
The vulnerability in the Mfc_Transceive function of phNxpExtns_MifareStd.cpp can result in an out-of-bounds read, leading to potential local information disclosure without extra execution privileges.
The Impact of CVE-2019-2135
Technical Details of CVE-2019-2135
Vulnerability Description
The vulnerability allows for an out-of-bounds read in the Mfc_Transceive function, potentially leading to information disclosure.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates