CVE-2018-9496: Critical severity Google Android vulnerability
Published Oct 1, 2018
·Updated
In ixheaacdrealsynthfftp3 of ixheaacdesbrfft.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-9.0 Android ID: A-110769924
Affected Software
2 affected components
Google Android=9.0
Google Android
Remediation
Patch Available
Event History
Oct 1, 2018
CVE Published
via Android·12:00 AM
Oct 2, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android versions are identified as affected?
Android 9.0 is identified as affected.
2
What conditions are required for exploitation?
Exploitation requires user interaction. It does not require additional execution privileges.
3
Is a fix available?
Yes. A patch is available.