First published: Fri Mar 30 2018(Updated: )
On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code execution in a privileged process, aka SVE-2017-10991.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Mobile | =6.0 | |
Samsung Mobile | =7.0 | |
Samsung Mobile | =7.1 | |
Samsung Mobile | =7.1.1 | |
Samsung Mobile | =7.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9143 is classified as a high-severity vulnerability due to its potential to allow code execution in a privileged process.
To fix CVE-2018-9143, users should update their Samsung mobile devices to the latest available software version that addresses this vulnerability.
CVE-2018-9143 affects Samsung mobile devices running Android versions 6.0 (M) and 7.x (N), specifically various builds of version 7.0, 7.1, and 7.1.x.
An attacker exploiting CVE-2018-9143 can execute arbitrary code in a privileged process, potentially compromising the security of the device.
Yes, Samsung has released patches for CVE-2018-9143 in their security updates for the affected mobile device models.