PT-2018-19047 · Google · Android
Published
2018-12-06
·
Updated
2019-01-02
·
CVE-2018-9554
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android versions 7.0 through 8.1
Description
The issue concerns a permissions bypass in the
dumpExtractors function of IMediaExtractor.cp, potentially leading to the disclosure of recently accessed media files. This could result in local information disclosure without requiring additional execution privileges. User interaction is not necessary for exploitation.Recommendations
For Android versions 7.0 through 8.1, consider restricting access to sensitive media files as a temporary mitigation measure until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android