In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://source.android.com/security/bulletin/2018-07-01 | patch vendor advisory |