First published: Tue Sep 04 2018(Updated: )
In intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | =8.0 | |
Google Android | =8.1 | |
Google Android | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9482 has been classified as having moderate severity due to the potential for local information disclosure.
To fix CVE-2018-9482, update your Android device to the latest version that addresses this vulnerability.
CVE-2018-9482 affects Google Android versions 8.0, 8.1, and 9.0.
No, user interaction is not needed for the exploitation of CVE-2018-9482.
CVE-2018-9482 is an out-of-bounds read vulnerability that can lead to information disclosure.