In opencv calls that use libpng, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges required. User interaction is not required for exploitation. Product: AndroidVersions: Android-10Android ID: A-110986616
No PoCs from references.
- https://github.com/Live-Hack-CVE/CVE-2019-9423
- https://github.com/vladislav-serdyuk/AR_headset