CVE-2018-9487: Medium severity Google Android vulnerability
In setVpnForcedLocked of Vpn.java, there is a possible blocking of internet traffic through vpn due to a bad uid check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9487?
CVE-2018-9487 is classified as a low-severity vulnerability that can lead to a local denial of service.
How do I fix CVE-2018-9487?
To fix CVE-2018-9487, update your Android device to a version that includes the security patch addressing this vulnerability.
Which versions of Android are affected by CVE-2018-9487?
CVE-2018-9487 affects Android versions 8.0, 8.1, and 9.0.
What is the impact of CVE-2018-9487?
The impact of CVE-2018-9487 is that it can block internet traffic through a VPN, causing local denial of service without requiring additional privileges.
Is user interaction required for CVE-2018-9487 exploitation?
Yes, user interaction is needed for the exploitation of CVE-2018-9487.