CVE-2018-9498: Integer Overflow
In SkSampler::Fill of SkSampler.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78354855
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Which Android versions are affected, and what access does an attacker need?
Android 7.0, 7.1.1, 7.1.2, 8.0, and 8.1 are listed as affected. Exploitation requires user interaction but does not require the attacker to have additional execution privileges.
What is the potential impact of successful exploitation?
The vulnerability is an integer overflow in SkSampler::Fill that can cause an out-of-bounds write. A successful exploit could result in remote code execution with high impact to confidentiality, integrity, and availability.
What should organizations do to remediate this issue?
A patch is available. Apply the available Android security update for the affected device or build.