CVE-2018-9486: Medium severity Google Android vulnerability
In hidhl2cifdataind of hidhconn.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9486?
CVE-2018-9486 is categorized as a medium severity vulnerability due to possible local information disclosure without required user interaction.
How do I fix CVE-2018-9486?
To remediate CVE-2018-9486, update your Android device to the latest security patch provided by Google.
Which versions of Android are affected by CVE-2018-9486?
CVE-2018-9486 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
Can CVE-2018-9486 be exploited remotely?
CVE-2018-9486 requires the attacker to be in proximity to the victim's device due to the nature of the Bluetooth vulnerability.
What type of information could be disclosed through CVE-2018-9486?
CVE-2018-9486 could potentially lead to the local disclosure of sensitive information over Bluetooth.