Description
In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Problem types
Denial of service
Product status
15
14
13
References
android.googlesource.com/...fcecb19f3a19caaba4285e059f32d2dd
source.android.com/security/bulletin/2025-04-01