PT-2018-19021 · Google · Android

Published

2018-11-06

·

Updated

2020-08-24

·

CVE-2018-9488

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions 8.0 through 9.0
Description A permissions bypass issue exists in the SELinux permissions of crash dump.te due to a missing restriction. This could lead to a local escalation of privilege, requiring System privileges. User interaction is not needed for exploitation.
Recommendations For Android versions 8.0 through 9.0, update to a version that includes the fix for the permissions bypass issue in crash dump.te to prevent local escalation of privilege.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-9488

Affected Products

Android