CVE-2018-9488
published 2018-11-06CVE-2018-9488: In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of privilege…
PriorityP343high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
0.43%
34.4th percentile
In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of privilege, with System privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9.0 Android ID: A-110107376.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2018-9488: Android Security Bulletin 2018-09-01
CVE: CVE-2018-9488
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 8
vendor_android·2018-09-01·CVSS 7.8
CVE-2018-9488 [HIGH] CVE-2018-9488: Android Security Bulletin 2018-09-01
CVE: CVE-2018-9488
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 8
Android Security Bulletin 2018-09-01
CVE: CVE-2018-9488
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 8.0, 8.1, 9
References: A-110107376
GHSA
GHSA-533r-f5fc-h9gv: In the SELinux permissions of crash_dump
ghsa_unreviewed·2022-05-13
CVE-2018-9488 [HIGH] CWE-863 GHSA-533r-f5fc-h9gv: In the SELinux permissions of crash_dump
In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of privilege, with System privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9.0 Android ID: A-110107376.
Project0
OATmeal on the Universal Cereal Bus: Exploiting Android phones over USB - Project Zero
project_zero·2018-09-01·CVSS 6.8
CVE-2018-9445 [MEDIUM] OATmeal on the Universal Cereal Bus: Exploiting Android phones over USB - Project Zero
Posted by Jann Horn, Google Project Zero
Recently, there has been some attention around the topic of physical attacks on smartphones, where an attacker with the ability to connect USB devices to a locked phone attempts to gain access to the data stored on the device. This blogpost describes how such an attack could have been performed against Android devices (tested with a Pixel 2).
After an Android phone has been unlocked once on boot (on newer devices, using the "Unlock for all features and data" screen; on older devices, using the "To start Android, enter your password" screen), it retains the encryption keys used to decrypt files in kernel memory even when the screen is locked, and the encrypted filesystem areas or partition(s) stay accessible. Therefore, an attacker who gains the
No detection rules found.
No writeups or analysis indexed.
2018-11-06
Published