The MetaIO SDK before 6.0.2.1 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-118,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| metaio | metaio_sdk | * |