First published: Mon Oct 01 2018(Updated: )
In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9.0 Android ID: A-111934948
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =8.0 | |
Google Android | =8.1 | |
Google Android | =9.0 | |
https://android.googlesource.com/platform/frameworks/base/+/962fb40991f15be4f688d960aa00073683ebdd20
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9492 is classified as a high severity vulnerability due to its potential for local escalation of privilege.
To fix CVE-2018-9492, users should update their Android devices to the latest security patches provided by Google.
CVE-2018-9492 affects Android versions 8.0, 8.1, and 9.0.
Yes, CVE-2018-9492 can be exploited without any user interaction, making it particularly dangerous.
CVE-2018-9492 allows a local attacker to potentially bypass permissions and escalate privileges, compromising device security.