CVE-2018-9357: High severity Google Android vulnerability
In BNEPWrite of bnepapi.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74947856.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9357?
CVE-2018-9357 has a moderate severity level due to its potential for local escalation of privilege.
How do I fix CVE-2018-9357?
To fix CVE-2018-9357, users should update their Android device to a patched version released by Google.
Which versions of Android are affected by CVE-2018-9357?
CVE-2018-9357 affects Android versions 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
Can CVE-2018-9357 be exploited without user interaction?
Yes, CVE-2018-9357 does not require user interaction for exploitation.
What kind of attack does CVE-2018-9357 facilitate?
CVE-2018-9357 facilitates local escalation of privilege attacks by allowing out of bounds write access.