CVE-2018-9428: Use After Free
Published Jul 2, 2018
·Updated
In startDevice of AAudioServiceStreamBase.cpp there is a possible out of bounds write due to a use after free. This could lead to local arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation. https://source.android.com/security/bulletin/2018-07-01
Affected Software
2 affected components
Google Android
Google Android=8.1
Event History
Jul 2, 2018
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 19, 2024
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-9428?
CVE-2018-9428 has a severity rating of high due to the potential for local arbitrary code execution.
2
How do I fix CVE-2018-9428?
To fix CVE-2018-9428, update your Android device to the latest security patch provided by Google.
3
What causes the CVE-2018-9428 vulnerability?
CVE-2018-9428 is caused by a use after free condition in the startDevice function of AAudioServiceStreamBase.cpp.
4
Is user interaction required to exploit CVE-2018-9428?
Yes, user interaction is required for the exploitation of CVE-2018-9428.
5
Which versions of Android are affected by CVE-2018-9428?
CVE-2018-9428 specifically affects Android version 8.1.