CVE-2018-9490
Last modified
CVE-2018-9490 is a vulnerability of currently unknown severity. In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type confusion. This could lead to remote escalation of privilege with no additional execution privileges needed. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type confusion. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111274046
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 7.0 | |
| Android | 7.1.1 | |
| Android | 7.1.2 | |
| Android | 8.0 | |
| Android | 8.1 | |
| Android | 9.0 |
References
- http://www.securityfocus.com/bid/105484Third Party Advisory, VDB Entry
- https://android.googlesource.com/platform/external/v8/+/a24543157ae2cdd25da43e20f4e48a07481e6cebPatch, Third Party Advisory
- http://www.securityfocus.com/bid/105484Third Party Advisory, VDB Entry
- https://android.googlesource.com/platform/external/v8/+/a24543157ae2cdd25da43e20f4e48a07481e6cebPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-9490?
How severe is CVE-2018-9490?
How do I fix CVE-2018-9490?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-9484In l2cu_send_peer_config_rej of l2c_utils.cc, there is a pos…7.5
- CVE-2018-9485In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible…6.5
- CVE-2018-9486In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible …6.5
- CVE-2018-9487In setVpnForcedLocked of Vpn.java, there is a possible block…5.5
- CVE-2018-9488In the SELinux permissions of crash_dump.te, there is a perm…
- CVE-2018-9489When wifi is switched, function sendNetworkStateChangeBroadc…
- CVE-2018-9491In AMediaCodecCryptoInfo_new of NdkMediaCodec.cpp, there is …
- CVE-2018-9492In checkGrantUriPermissionLocked of ActivityManagerService.j…
- CVE-2018-9493In the content provider of the download manager, there is a …
- CVE-2018-9496In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there i…
- CVE-2018-9497In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_form…
- CVE-2018-9498In SkSampler::Fill of SkSampler.cpp, there is a possible out…
Are you affected by CVE-2018-9490?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
