Out-of-bounds write in Google Android - CVE-2020-25278
Published: September 12, 2020 / Updated: September 22, 2020
Google Android
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The Quram image codec library allows attackers to overwrite memory and execute arbitrary code via crafted JPEG data that is mishandled during decoding. The Samsung IDs are SVE-2020-18088, SVE-2020-18225, SVE-2020-18301 (September 2020).