CVE-2018-9526
published 2018-11-14CVE-2018-9526: In device configuration data, there is an improperly configured setting. This could lead to remote disclosure of device location. User interaction is not…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
0.91%
56.0th percentile
In device configuration data, there is an improperly configured setting. This could lead to remote disclosure of device location. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112159033
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9m6f-gwxw-gqc9: In device configuration data, there is an improperly configured setting
ghsa_unreviewed·2022-05-14
CVE-2018-9526 [HIGH] CWE-200 GHSA-9m6f-gwxw-gqc9: In device configuration data, there is an improperly configured setting
In device configuration data, there is an improperly configured setting. This could lead to remote disclosure of device location. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112159033
Android
CVE-2018-9526: Android Security Bulletin 2019-06-01
CVE: CVE-2018-9526
Severity: HIGH
Type: ID
Affected AOSP versions: 7
vendor_android·2019-06-01·CVSS 7.5
CVE-2018-9526 [HIGH] CVE-2018-9526: Android Security Bulletin 2019-06-01
CVE: CVE-2018-9526
Severity: HIGH
Type: ID
Affected AOSP versions: 7
Android Security Bulletin 2019-06-01
CVE: CVE-2018-9526
Severity: HIGH
Type: ID
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-112159033
[2]
[3]
[4]
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-11-14
Published