๐Ÿ” CVE Alert

CVE-2025-34449

UNKNOWN 0.0

Genymobile/scrcpy <= 3.3.3 Global Buffer Overflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory corruption or a denial-of-service condition. This vulnerability may allow further exploitation on the host system.

CWE CWE-502
Vendor genymobile
Product scrcpy
Published Dec 18, 2025
Last Updated Mar 23, 2026
Stay Ahead of the Next One

Get instant alerts for genymobile scrcpy

Be the first to know when new unknown vulnerabilities affecting genymobile scrcpy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Genymobile / scrcpy
0 โ‰ค 3.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-003-scrcpy-global-buffer-overflow.md github.com: https://github.com/Genymobile/scrcpy/issues/6415 github.com: https://github.com/Genymobile/scrcpy/commit/3e40b24 vulncheck.com: https://www.vulncheck.com/advisories/genymobile-scrcpy-global-buffer-overflow

Credits

Vlatko Kosturjak with Marlink Cyber