
Cloud Vulnerability DB
A community-led vulnerabilities database
Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption (Samsung Mobile, NVD). The vulnerability was discovered on July 31, 2024 and affects Android versions 12, 13, and 14.
The vulnerability is classified as High severity with a CVSS v3.1 base score of 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). It is identified as CWE-787 (Out-of-bounds Write) and affects the libsapeextractor.so library component (NVD).
The vulnerability allows local attackers to cause memory corruption, which could potentially lead to arbitrary code execution with elevated privileges. The impact affects confidentiality, integrity, and availability of the system (NVD).
The vulnerability has been patched in SMR Nov-2024 Release 1 through the addition of proper input validation (Samsung Mobile). Users should update their devices to the latest security patch level to mitigate this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."