CVE-2018-9433: Input Validation
In ArrayConcatVisitor of builtins-array.cc, there is a possible type confusion due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9433?
CVE-2018-9433 is rated as a critical severity vulnerability as it can lead to remote code execution.
How do I mitigate CVE-2018-9433?
Mitigation for CVE-2018-9433 involves updating to the latest version of Android that addresses this vulnerability.
Who is affected by CVE-2018-9433?
CVE-2018-9433 affects users running specific versions of Google Android, including 6.0, 6.0.1, 7.0, and 7.1.x.
Can CVE-2018-9433 be exploited without user interaction?
Exploitation of CVE-2018-9433 requires user interaction, making it less likely but still possible.
What type of vulnerability is CVE-2018-9433?
CVE-2018-9433 is a type confusion vulnerability that arises from improper input validation.