CVE-2018-9593: Medium severity Google Android vulnerability
In llcpdlcprocipdu of llcpdlc.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over NFC with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-116722267.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9593?
CVE-2018-9593 is classified as a medium-severity vulnerability due to its potential for local information disclosure.
How do I fix CVE-2018-9593?
To fix CVE-2018-9593, update the affected Android devices to the latest security patches provided by Google.
Which Android versions are affected by CVE-2018-9593?
CVE-2018-9593 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
What type of vulnerability is CVE-2018-9593?
CVE-2018-9593 is an out-of-bounds read vulnerability in the NFC implementation of Android.
Can CVE-2018-9593 be exploited remotely?
CVE-2018-9593 requires local access to exploit, specifically through NFC, so it is not a remote vulnerability.