← Back

CVE-2018-9508

nvd nist
Published: Oct 2, 2018Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

In smp_process_keypress_notification of smp_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-111936834

Affected (5)

Products: Google: Android
1 product
Android
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 7.0
Version 7.1.1
Version 7.1.2
Version 8.0
Version 8.1

References (7)

Source: security@android.com
Third Party AdvisoryVDB Entry
Source: nvd@nist.gov
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.