CVE-2018-9583: Critical severity Google Android vulnerability
In btaagparsecmer of btaagcmd.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution in the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-112860487.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9583?
CVE-2018-9583 has a severity rating that indicates a high risk of remote code execution due to the out-of-bounds write vulnerability.
How do I fix CVE-2018-9583?
To mitigate CVE-2018-9583, you should update to a patched version of Android that fixes the out-of-bounds write issue.
Which Android versions are affected by CVE-2018-9583?
CVE-2018-9583 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
Can CVE-2018-9583 be exploited remotely?
Yes, CVE-2018-9583 can be exploited remotely, allowing an attacker to execute code on the vulnerable Bluetooth server.
What is the impact of CVE-2018-9583?
The impact of CVE-2018-9583 includes the potential for remote code execution without requiring additional execution privileges.