CVE-2018-9523: Input Validation
Published Nov 5, 2018
·Updated
In Parcel.writeMapInternal of Parcel.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112859604
Affected Software
7 affected components
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android
Remediation
Patch Available
Event History
Nov 5, 2018
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 14, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs local access and low-level privileges on an affected Android device. No user interaction or additional execution privileges are required.
2
Which Android releases are affected?
Affected releases are Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.
3
What should be done to remediate the issue?
Apply the available patch for Android ID A-112859604.