CVE-2018-9591: High severity Google Android vulnerability
In btahhctrldatact of btahhact.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-116108738.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The issue is remotely exploitable with no privileges and requires no user interaction. Successful exploitation can disclose information through an out-of-bounds read.
Which Android releases are identified as affected?
The affected releases listed are Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.
Does exploitation affect confidentiality, integrity, or availability?
The CVSS vector indicates high confidentiality impact, with no integrity or availability impact. The described outcome is remote information disclosure.