Information disclosure in Google Android - CVE-2018-9489
Published: August 30, 2018 / Updated: August 31, 2018
Google Android
Detailed vulnerability description
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to local application can monitor NETWORK_STATE_CHANGED_ACTION and WIFI_P2P_THIS_DEVICE_CHANGED_ACTION system WiFi broadcasts. A local attacker can obtain identifying data on the target system, including network names, BSSIDs, local addresses, and DNS server addresses.