Information disclosure in Google Android - CVE-2018-9499

 

Information disclosure in Google Android - CVE-2018-9499

Published: October 2, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36574
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-9499
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to gain access to sensitive information.

In readVector of iCrypto.cpp, there is a possible invalid read due to uninitialized data. This could lead to local information disclosure from the DRM server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-79218474


Affected software

Google Android

How to mitigate CVE-2018-9499

Install update from vendor's website.


External References

Related Security Bulletins