EXPOSURES › CVE-2019-2215
CVE-2019-2215
HIGH ⌖ ON CISA KEV · EXPLOITEDA use-after-free vulnerability in the Android kernel allowed privilege escalation from an app to the Linux kernel, often chained with other CVEs to gain full control.
This kernel-level flaw in binder.c enabled attackers to escalate privileges from a malicious app to the Linux kernel, potentially achieving root access. DIB organizations must ensure all mobile devices and endpoints run patched OS versions, as this class of vulnerability is frequently chained with others to bypass security controls. The failure highlights the risk of relying on unpatched mobile devices for sensitive operations.
Shame score — A kernel-level privilege escalation flaw that was actively exploited in the wild and chained with other vulnerabilities to achieve full device control, indicating a severe and avoidable security gap.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
"Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain 'AbstractEmu.'"