CVE-2018-9483: Use After Free
In btadmremovesecdeventry of btadmact.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9483?
CVE-2018-9483 is considered a moderate severity vulnerability due to the potential for remote information disclosure over Bluetooth.
How do I fix CVE-2018-9483?
To fix CVE-2018-9483, update your Android device to the latest security patch that addresses this vulnerability.
Which versions of Android are affected by CVE-2018-9483?
CVE-2018-9483 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
What causes CVE-2018-9483?
CVE-2018-9483 is caused by a use after free vulnerability in the Bluetooth stack, specifically in the function bta_dm_remove_sec_dev_entry.
Is user interaction required for the exploitation of CVE-2018-9483?
No, user interaction is not needed for exploitation of CVE-2018-9483.