PT-2024-10652 · Google · Android

Published

2024-11-28

·

Updated

2025-01-17

·

CVE-2018-9377

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions prior to the fixed version
Description The issue allows for local escalation of privilege or information disclosure due to uninitialized data or a pending intent. This could lead to accessing user metadata or local information disclosure with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations For Android versions prior to the fixed version, consider restricting access to sensitive data and metadata to minimize the risk of exploitation. As a temporary workaround, consider disabling the getIntentForIntentSender function in ActivityManagerService.java until a patch is available. Avoid using uninitialized data in BnAudioPolicyService::onTransact of IAudioPolicyService.cpp to prevent information disclosure.

Fix

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

CVE-2018-9377

Affected Products

Android