SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-9277

In the proc filesystem, there is a possible information disclosure due to log information disclosure.

LOW 3.3EPSS 0.18%

Does this matter?

Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.

Description

In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-68016944

CVSS 3.1
3.3 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.18% probability · 7th percentile
CISA KEV
Not listed
Weakness
CWE-532
Affected
google/android
Source
security@android.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.