CVE-2018-9508

MEDIUM

Google Android - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

In smp_process_keypress_notification of smp_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-111936834

References (4)

Core 4

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 48.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-125
Status published
Products (5)
google/android 7.0
google/android 7.1.1
google/android 7.1.2
google/android 8.0
google/android 8.1
Published Oct 02, 2018
Tracked Since Feb 18, 2026