CVE-2018-9550: High severity Google Android vulnerability
Published Dec 3, 2018
·Updated
In CAacDecoderInit of aacdecoder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112660981.
Affected Software
2 affected components
Google Android=9.0
Google Android
Event History
Dec 3, 2018
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Dec 6, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-9550?
CVE-2018-9550 is considered a high severity vulnerability that could lead to remote code execution.
2
How do I fix CVE-2018-9550?
To fix CVE-2018-9550, users should update their Android device to the latest security patch provided by Google.
3
What versions of Android are affected by CVE-2018-9550?
CVE-2018-9550 affects Android version 9.0.
4
What are the potential consequences of CVE-2018-9550?
Exploitation of CVE-2018-9550 could allow attackers to execute arbitrary code on affected devices.
5
Is user interaction needed to exploit CVE-2018-9550?
Yes, user interaction is required to exploit CVE-2018-9550.