CVE-2018-9427: Critical severity Google Android vulnerability
Published Aug 6, 2018
·Updated
In CopyToOMX of OMXNodeInstance.cpp there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-77486542.
Affected Software
3 affected components
Google Android=8.0
Google Android=8.1
Google Android
Remediation
Patch Available
Event History
Aug 6, 2018
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 6, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases are identified as affected?
The affected releases listed are Android 8.0 and Android 8.1.
2
What conditions are required for exploitation?
The CVSS vector indicates local attack access and required user interaction. No privileges are required before exploitation.
3
What impact could successful exploitation have?
Successful exploitation could result in arbitrary code execution with high confidentiality, integrity, and availability impact.
4
Is a fix available?
Yes. A patch is available for this issue.