CVE-2018-9432: High severity Google Android vulnerability
In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to local escalation of privilege due to hiding and bypassing the user's ability to disable access to contacts, with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9432?
CVE-2018-9432 is considered to be a medium severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2018-9432?
To fix CVE-2018-9432, update your Android device to the latest version provided by Google that addresses this vulnerability.
Which Android versions are affected by CVE-2018-9432?
CVE-2018-9432 affects Android versions 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
What type of vulnerability is CVE-2018-9432?
CVE-2018-9432 is a permissions bypass vulnerability related to Bluetooth permissions that can lead to local escalation of privileges.
Who is the vendor associated with CVE-2018-9432?
The vendor associated with CVE-2018-9432 is Google, specifically in their Android operating system.