CVE-2018-9377: High severity android vulnerability
Published Nov 28, 2024
·Updated
In getIntentForIntentSender of ActivityManagerService.java, there is a possible way to access user metadata due to a pending intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
2 affected components
Google Android=6.0
Google Android=6.0.1
Event History
Nov 28, 2024
CVE Published
via MITRE·12:23 AM
Data Sourced
via MITRE·12:23 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Oct 27, 57234
Event
via NVD·03:12 PM
Frequently Asked Questions
1
What is the severity of CVE-2018-9377?
CVE-2018-9377 has a medium severity rating due to its potential for local escalation of privilege.
2
How do I fix CVE-2018-9377?
To fix CVE-2018-9377, update your Android device to the latest security patch provided by Google.
3
Which versions of Android are affected by CVE-2018-9377?
CVE-2018-9377 affects Google Android versions 6.0 and 6.0.1.
4
Can CVE-2018-9377 be exploited without user interaction?
Yes, CVE-2018-9377 can be exploited without any user interaction required.
5
What impact does CVE-2018-9377 have on system security?
CVE-2018-9377 can lead to unauthorized access to user metadata, posing a risk to system security.