First published: Mon Apr 02 2018(Updated: )
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71360761.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | =6.0 | |
Google Android | =6.0.1 | |
Google Android | =7.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Google Android | =8.0 | |
Google Android | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-13274 has been classified with a moderate severity level due to the potential for incorrect security decisions.
To fix CVE-2017-13274, ensure that your Android system is updated to a version that addresses this vulnerability.
CVE-2017-13274 affects Android versions 6.0, 6.0.1, 7.0, 7.1.x, as well as 8.0 and 8.1.
Yes, CVE-2017-13274 can be exploited without any user interaction required.
The vulnerability in CVE-2017-13274 originates from the getHost() function in UriTest.java.