First published: Mon Oct 01 2018(Updated: )
In bta_av_proc_meta_cmd of bta_av_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111893951
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =7.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Google Android | =8.0 | |
Google Android | =8.1 | |
Google Android | =9.0 | |
https://android.googlesource.com/platform/system/bt/+/30cec963095366536ca0b1306089154e09bfe1a9
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9507 has a moderate severity level due to its potential for remote information disclosure without requiring user interaction.
To fix CVE-2018-9507, update your Android device to the latest security patch released after October 2018.
CVE-2018-9507 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
Yes, CVE-2018-9507 can be exploited remotely without any user interaction required.
CVE-2018-9507 is classified as an out of bounds read vulnerability that can lead to information disclosure.