CVE-2019-2119: Google Android

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This could lead to local information disclosure of protected data with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-131622568.

Affected products

  • Google Android: version 8.0 only; version 8.1 only; version 9.0 only

Published 2019-07-08. Last modified 2026-06-17.