CVE-2018-9338: High severity Google Android vulnerability
In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9338?
CVE-2018-9338 is classified as a moderate vulnerability that could lead to local escalation of privilege.
How do I fix CVE-2018-9338?
To fix CVE-2018-9338, update your Android device to the latest available version that addresses this vulnerability.
What software versions are affected by CVE-2018-9338?
CVE-2018-9338 affects various Android versions including 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
Is user interaction required to exploit CVE-2018-9338?
No, user interaction is not needed for the exploitation of CVE-2018-9338.
What can an attacker achieve by exploiting CVE-2018-9338?
An attacker can exploit CVE-2018-9338 to gain local escalation of privilege without requiring additional execution privileges.