CVE-2018-9582: High severity Google Android vulnerability
In package installer in Android-8.0, Android-8.1 and Android-9, there is a possible bypass of the unknown source warning due to a confused deputy scenario. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-112031362.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker needs local access with low privileges. Exploitation does not require user interaction or additional execution privileges.
What is the impact of successful exploitation?
A successful exploit can bypass the unknown-source warning in the package installer and result in local privilege escalation with high confidentiality, integrity, and availability impact.
Which Android releases are affected?
The affected releases are Android 8.0, Android 8.1, and Android 9.
How can I track this issue in Android security documentation?
This issue is identified as Android ID A-112031362 and was published in the Android security bulletin dated 2019-01-01.