First published: Tue Sep 04 2018(Updated: )
In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | =7.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Google Android | =8.0 | |
Google Android | =8.1 | |
Google Android | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9471 has a medium severity rating due to potential local escalation of privilege.
To fix CVE-2018-9471, upgrade to a patched version of Android that addresses this vulnerability.
CVE-2018-9471 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
No, user interaction is not needed to exploit CVE-2018-9471.
Exploiting CVE-2018-9471 could lead to local escalation of privilege in the system server.