First published: Fri Sep 27 2019(Updated: )
In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE and android.net.wifi.STATE_CHANGE intents. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111698366
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-9581 is considered medium due to its potential for local information disclosure.
CVE-2018-9581 affects Android version 10.0 systems.
To fix CVE-2018-9581, update your Android device to the latest version provided by Google.
CVE-2018-9581 is an information disclosure vulnerability related to the broadcasting of RSSI value and SSID.
No, user interaction is not needed for exploitation of CVE-2018-9581.