CVE-2018-9522Out-of-bounds Write in INC Android

Severity
7.8HIGHNVD
EPSS
0.0%
top 95.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 14

Description

In the serialization functions of StatsLogEventWrapper.java, there is a possible out-of-bounds write due to unnecessary functionality which may be abused. This could lead to local escalation of privilege in the system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112550251

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5google_inc/androidAndroid-9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9p67-cmxj-h92h: In the serialization functions of StatsLogEventWrapper2022-05-14
CVEList
CVE-2018-9522: In the serialization functions of StatsLogEventWrapper2018-11-14

📋Vendor Advisories

1
Android
CVE-2018-9522: Android Security Bulletin 2018-11-01 CVE: CVE-2018-9522 Severity: HIGH Type: EoP Affected AOSP versions: 9 References: A-1125502512018-11-01
CVE-2018-9522 — Out-of-bounds Write in INC Android | cvebase