CVE-2019-12936: Bluestacks App Player

High severity, CVSS 8.0. EPSS: 3.5% chance of exploitation in the next 30 days.

BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions.

Affected products

  • Bluestacks Bluestacks App Player: before 4.90 (fixed in 4.90)

Published 2019-06-23. Last modified 2026-06-17.