CVE-2018-9551: High severity Google Android vulnerability
In CAacDecoderInit of aacdecoder.cpp, there is a possible out-of-bound write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112891548.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9551?
CVE-2018-9551 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2018-9551?
To fix CVE-2018-9551, update your Android device to the latest software version that addresses this vulnerability.
What products are affected by CVE-2018-9551?
CVE-2018-9551 primarily affects devices running Android 9.0.
What type of attack is associated with CVE-2018-9551?
CVE-2018-9551 is associated with an out-of-bounds write vulnerability that could be exploited for remote code execution.
Is user interaction required to exploit CVE-2018-9551?
Yes, user interaction is required for the exploitation of CVE-2018-9551 in the media server.