CVE-2018-9435: Medium severity android vulnerability
In gattprocesserrorrsp of gattcl.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9435?
CVE-2018-9435 is classified as a moderate severity vulnerability due to the potential for local information disclosure.
How do I fix CVE-2018-9435?
To fix CVE-2018-9435, you should update to the latest patched version of Android provided by Google, specifically those newer than the affected versions.
Which versions of Android are affected by CVE-2018-9435?
Affected versions by CVE-2018-9435 include Android 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
What type of attack can exploit CVE-2018-9435?
CVE-2018-9435 can be exploited to perform local information disclosure without requiring additional execution privileges.
Does CVE-2018-9435 require user interaction to exploit?
No, CVE-2018-9435 does not require user interaction for exploitation.