---
id: CVE-2025-34449
title: >-
  Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24,
  contain a buffer overflow vulnerability in the sc_device_msg_deserialize()
  function
summary: >-
  Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24,
  contain a buffer overflow vulnerability in the sc_device_msg_deserialize()
  function. A compromised device can send crafted messages that cause
  out-of-bounds r…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-502
  - CWE-502
vendor: genymotion
product: scrcpy
affected:
  - scrcpy < 3.3.4
patched:
  - scrcpy 3.3.4
published: '2025-12-18'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34449'
references:
  - url: 'https://github.com/Genymobile/scrcpy/commit/3e40b24'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Genymobile/scrcpy/issues/6415'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-003-scrcpy-global-buffer-overflow.md
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/genymobile-scrcpy-global-buffer-overflow
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-003-scrcpy-global-buffer-overflow.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0042
epssPercentile: 0.33917
ingestedAt: '2026-09-30T23:29:32.505Z'
---

## Overview

Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory corruption or a denial-of-service condition. This vulnerability may allow further exploitation on the host system.

## Affected

- `scrcpy < 3.3.4`

## Remediation

Upgrade past the affected range:

- `scrcpy 3.3.4`
