CVE-2018-9592: High severity Google Android vulnerability
Published Jan 1, 2019
·Updated
In mcaccbhdlrsp of mcacact.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-116319076.
Affected Software
7 affected components
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android
Event History
Jan 7, 2019
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Feb 12, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is remotely exploitable over the network with low attack complexity. It requires no privileges and no user interaction.
2
What is the potential impact of successful exploitation?
Successful exploitation could disclose information through an out-of-bounds read. The provided CVSS vector indicates high confidentiality impact, with no integrity or availability impact.
3
Which Android releases are identified as affected?
The affected releases listed are Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.