PT-2024-10652 · Google · Android
Published
2024-11-28
·
Updated
2025-01-17
·
CVE-2018-9377
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions prior to the fixed version
Description
The issue allows for local escalation of privilege or information disclosure due to uninitialized data or a pending intent. This could lead to accessing user metadata or local information disclosure with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations
For Android versions prior to the fixed version, consider restricting access to sensitive data and metadata to minimize the risk of exploitation.
As a temporary workaround, consider disabling the
getIntentForIntentSender function in ActivityManagerService.java until a patch is available.
Avoid using uninitialized data in BnAudioPolicyService::onTransact of IAudioPolicyService.cpp to prevent information disclosure.Fix
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android