CVE-2018-9527: Critical severity Google Android vulnerability
In vorbisbookdecodevset of codebook.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112159345
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Which Android devices are exposed and what does an attacker need?
Devices running Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, or 9 are listed as affected. Exploitation requires user interaction, but does not require the attacker to have additional execution privileges.
What is the impact and is a fix available?
The flaw is an out-of-bounds write in vorbis_book_decodev_set in codebook.c, which can lead to remote code execution with high impact to confidentiality, integrity, and availability. A patch is available.