Impact
An off-by-one error in GNU Emacs for Android’s gvar table parser allows a malicious TrueType variable font to skip a shared‑coordinate index boundary check. This results in a heap‑based out‑of‑bounds read that can leak heap contents, which an attacker may use to defeat address space layout randomization.
Affected Systems
All GNU Emacs for Android installations that have not applied the fix committed as 95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe. No specific version line numbers are listed, so any pre‑fix instance is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not currently a widely used exploit. Attacks require delivery of a crafted font file through email, the Emacs Web Wowser, or document files that Emacs processes. The open‑source nature of the software means that the vulnerability is easily reproducible, but no documented exploits are known. The primary risk is the exposure of heap memory that can undermine ASLR protections.
OpenCVE Enrichment