CVE-2018-9469: High severity Google Android vulnerability
In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead to local escalation of privilege in a privileged app with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9469?
CVE-2018-9469 has a medium severity rating as it allows the creation of spoofed shortcuts leading to local escalation of privileges.
How do I fix CVE-2018-9469?
To fix CVE-2018-9469, update to the latest version of Android that addresses the missing permission check.
What versions of Android are affected by CVE-2018-9469?
CVE-2018-9469 affects Android versions 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
What kind of exploitation is possible with CVE-2018-9469?
CVE-2018-9469 may allow an attacker to spoof shortcuts, requiring user interaction for exploitation.
Is user interaction required for CVE-2018-9469 exploitation?
Yes, user interaction is needed for the exploitation of CVE-2018-9469.