{"id":"CVE-2025-34449","title":"Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function","summary":"Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds r…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-502","CWE-502"],"vendor":"genymotion","product":"scrcpy","affected":["scrcpy < 3.3.4"],"patched":["scrcpy 3.3.4"],"published":"2025-12-18","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-34449","references":[{"url":"https://github.com/Genymobile/scrcpy/commit/3e40b24","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Genymobile/scrcpy/issues/6415","label":"disclosure@vulncheck.com"},{"url":"https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-003-scrcpy-global-buffer-overflow.md","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/genymobile-scrcpy-global-buffer-overflow","label":"disclosure@vulncheck.com"},{"url":"https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-003-scrcpy-global-buffer-overflow.md","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.0042,"epssPercentile":0.33917,"ingestedAt":"2026-09-30T23:29:32.505Z","slug":"CVE-2025-34449","body":"## Overview\n\nGenymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory corruption or a denial-of-service condition. This vulnerability may allow further exploitation on the host system.\n\n## Affected\n\n- `scrcpy < 3.3.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `scrcpy 3.3.4`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}