VYPR
Unrated severityNVD Advisory· Published Sep 27, 2019· Updated Aug 4, 2024

CVE-2019-2161

CVE-2019-2161

Description

In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112553431

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds read in libxaac on Android 10 could lead to information disclosure via a crafted media file.

Vulnerability

The vulnerability exists in libxaac, the AAC audio decoder library on Android 10. A missing bounds check allows an out-of-bounds read when processing a specially crafted audio file. This affects Android 10 (security patch level 2019-09-01 or earlier). The issue is identified as Android ID A-112553431.

Exploitation

An attacker must convince a user to open a malicious audio file (e.g., via a messaging app or web download). No additional execution privileges are required beyond normal user access. The user interaction is necessary to trigger the vulnerable code path in libxaac.

Impact

Successful exploitation could lead to information disclosure, potentially exposing sensitive data from the device's memory. The attacker gains no code execution or privilege escalation; the impact is limited to reading out-of-bounds memory.

Mitigation

The fix is included in Android 10 as released on AOSP with a security patch level of 2019-09-01. Users should ensure their device's security patch level is at least 2019-09-01. No workarounds are documented; updating to the latest Android version is recommended. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Google/Androiddescription
  • Google/libxaacllm-fuzzy
    Range: Android-10

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.