CVE-2018-9537: Critical severity Google Android vulnerability
In CAacDecoderDecodeFrame of aacdecode.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112891564
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
An attacker would need to cause a user to interact with malicious media content that reaches the AAC decoder. The issue is remotely exploitable and does not require the attacker to hold additional execution privileges.
What is the potential impact if exploitation succeeds?
Successful exploitation could allow remote code execution in the Android media server. The supplied CVSS vector indicates high impacts to confidentiality, integrity, and availability.
Which Android version is identified as affected?
The provided affected-version information identifies Android 9.
Is a fix available?
Yes. A patch is available, and the issue is associated with Android ID A-112891564.