First published: Tue Nov 06 2018(Updated: )
When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts an intent including detailed wifi network information. This could lead to information disclosure with no execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-77286245.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =7.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Google Android | =8.0 | |
Google Android | =8.1 | |
Google Android | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9489 is rated as a high-severity vulnerability due to its potential for information disclosure.
To mitigate CVE-2018-9489, update your Android device to the latest available version that has patched this vulnerability.
CVE-2018-9489 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
CVE-2018-9489 is an information disclosure vulnerability that allows detailed WiFi network information to be broadcasted.
No, exploitation of CVE-2018-9489 does not require any user interaction.