CVE-2018-9489
Last modified
CVE-2018-9489 is a vulnerability of currently unknown severity. When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts an intent including detailed wifi network information. This could lead to information disclosure with no execution privileges needed. EPSS estimates a 0.99% chance of exploitation in the next 30 days.
Description
When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts an intent including detailed wifi network information. This could lead to information disclosure with no execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-77286245.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 7.0 | |
| Android | 7.1.1 | |
| Android | 7.1.2 | |
| Android | 8.0 | |
| Android | 8.1 | |
| Android | 9.0 |
References
- http://www.securitytracker.com/id/1041590Third Party Advisory, VDB Entry
- https://wwws.nightwatchcybersecurity.com/2018/08/29/sensitive-data-exposure-via-wifi-broadcasts-in-android-os-cve-2018-9489/Mitigation, Third Party Advisory
- http://www.securitytracker.com/id/1041590Third Party Advisory, VDB Entry
- https://wwws.nightwatchcybersecurity.com/2018/08/29/sensitive-data-exposure-via-wifi-broadcasts-in-android-os-cve-2018-9489/Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-9489?
How severe is CVE-2018-9489?
How do I fix CVE-2018-9489?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-9483In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a …6.5
- CVE-2018-9484In l2cu_send_peer_config_rej of l2c_utils.cc, there is a pos…7.5
- CVE-2018-9485In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible…6.5
- CVE-2018-9486In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible …6.5
- CVE-2018-9487In setVpnForcedLocked of Vpn.java, there is a possible block…5.5
- CVE-2018-9488In the SELinux permissions of crash_dump.te, there is a perm…
- CVE-2018-9490In CollectValuesOrEntriesImpl of elements.cc, there is possi…
- CVE-2018-9491In AMediaCodecCryptoInfo_new of NdkMediaCodec.cpp, there is …
- CVE-2018-9492In checkGrantUriPermissionLocked of ActivityManagerService.j…
- CVE-2018-9493In the content provider of the download manager, there is a …
- CVE-2018-9496In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there i…
- CVE-2018-9497In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_form…
Are you affected by CVE-2018-9489?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
