What happened
In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected versions
Android: 14; 13; 12L; 12; 11; 11.0; 12.0; 12.0l; 13.0; 14.0 Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
SploitusExploit for CVE-2024-0023. CVSS 7.8.Sploitus index2026-09-09T20:01:46+00:00CandidateSource timeline
Discovered through SploitusView source ↗
CVE record published by NVDView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.