First published: Fri Sep 27 2019(Updated: )
In AOSP Email, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of the Email app's protected files with User execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-37637796
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9440 has been classified as a moderate severity vulnerability.
To mitigate CVE-2019-9440, it is recommended to update to the latest security patch for Android 10.
CVE-2019-9440 affects the AOSP Email application on Android 10.
CVE-2019-9440 is classified as an information disclosure vulnerability.
Yes, user interaction is required for the exploitation of CVE-2019-9440.