CVE-2018-9425

HIGH

Android 10 - Local Privilege Escalation via Missing Permission Checks

Title source: llm
STIX 2.1

Description

In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73884967

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 4.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
google/android 10.0
Published Sep 27, 2019
Tracked Since Feb 18, 2026