CVE-2026-4756
7.8MolotovCherry · Android-ImageMagick7
An out-of-bounds write vulnerability in MolotovCherry Android-ImageMagick7 allows for potential memory corruption and system compromise.
Executive summary
An out-of-bounds write vulnerability in MolotovCherry Android-ImageMagick7 poses a significant risk of memory corruption and arbitrary code execution.
Vulnerability
This is an out-of-bounds write vulnerability (CWE-787) occurring within the Android-ImageMagick7 library. The vulnerability requires user interaction to trigger, typically through the processing of a specially crafted image file.
Business impact
Successful exploitation of this out-of-bounds write vulnerability can lead to memory corruption, potentially resulting in application crashes or unauthorized code execution on the host system. Given the CVSS score of 7.8, this vulnerability is classified as High severity, representing a substantial risk to data integrity and system availability.
Remediation
Immediate Action: Update the Android-ImageMagick7 library to version 7.1.2-11 or later to resolve the underlying memory management flaw.
Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous behavior associated with image processing tasks.
Compensating Controls: Implement strict input validation or sandboxing for any services that utilize the ImageMagick library to process untrusted user-supplied image files.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this vulnerability, combined with its potential for memory corruption, necessitates immediate attention. Organizations should prioritize updating the affected Android-ImageMagick7 library to the patched version, 7.1.2-11, to eliminate the risk of exploitation.
More MolotovCherry CVEs
Sources
Originally found and disclosed by TITAN Team (titancaproject@gmail.com), per the CVE Program record.