First published: Mon Dec 02 2024(Updated: )
In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =6.0 | |
Android | =6.0.1 | |
Android | =7.0 | |
Android | =7.1.1 | |
Android | =7.1.2 | |
Android | =8.0 | |
Android | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9430 has a high severity due to its potential for remote code execution.
To address CVE-2018-9430, ensure that your device is updated to the latest security patches provided by Google.
CVE-2018-9430 affects Android versions 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
No, user interaction is not needed for the exploitation of CVE-2018-9430.
CVE-2018-9430 is classified as an out-of-bounds write vulnerability.