CVE-2018-9524: High severity Google Android vulnerability
Published Nov 5, 2018
·Updated
In functionality implemented in System UI, there are insufficient protections implemented around overlay windows. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1. Android ID: A-34170870
Affected Software
6 affected components
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Google Android=8.0
Google Android=8.1
Google Android
Remediation
Patch Available
Event History
Nov 5, 2018
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 14, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases are affected?
The issue affects Android 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
2
What access and conditions does an attacker need?
Exploitation is local and requires user interaction. No additional execution privileges are required.
3
What is the potential impact?
A successful exploit could allow local escalation of privilege and compromise confidentiality, integrity, and availability.
4
Is a fix available?
Yes. A patch is available; the Android security bulletin referenced is dated 2018-11-01.