HomeDefault status
unaffected
16
affected
15
affected
Description
In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Problem types
Information disclosure
Product status
16
15
References
android.googlesource.com/...b5e8736ec013a7d64e70f50e87649b52
source.android.com/security/bulletin/2025-12-01