CVE-2018-9541: High severity Google Android vulnerability
In avrcparsvendorrsp of avcrparsct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111450531
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Which Android releases are affected?
The affected releases are Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.
Can this be exploited remotely without user interaction or prior privileges?
Yes. The CVSS vector indicates network attack access, low attack complexity, no privileges required, and no user interaction required. The issue can expose information through the Bluetooth service.
What is the impact of successful exploitation?
Successful exploitation may cause remote information disclosure through an out-of-bounds read. The supplied CVSS vector indicates high confidentiality impact, with no integrity or availability impact.
Is a fix available?
Yes. A patch is available, and the issue is tracked as Android ID A-111450531.