CVE-2018-9485: Medium severity Google Android vulnerability
Published Sep 4, 2018
·Updated
In l2cbleprocesssigcmd of l2cble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
7 affected components
Google Android
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Google Android=8.0
Google Android=8.1
Google Android=9.0
Remediation
Patch Available
Event History
Sep 4, 2018
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 20, 2024
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-9485?
CVE-2018-9485 is considered to have a medium severity due to the potential for remote information disclosure via Bluetooth.
2
How do I fix CVE-2018-9485?
To mitigate CVE-2018-9485, update your Android device to the latest security patch provided by Google.
3
What versions of Android are affected by CVE-2018-9485?
CVE-2018-9485 impacts Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
4
Is user interaction required for exploiting CVE-2018-9485?
No, user interaction is not needed for the exploitation of CVE-2018-9485.
5
What kind of vulnerability is CVE-2018-9485 classified as?
CVE-2018-9485 is classified as an out of bounds read vulnerability affecting Bluetooth operations.