PoC Index

CVE-2018-9499

MEDIUM 5.5EPSS 0.3%

In readVector of iCrypto.cpp, there is a possible invalid read due to uninitialized data. This could lead to local information disclosure from the DRM server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-79218474

CVSS v3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
4.9 MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
EPSS
0.30% chance of exploitation in the next 30 days, 23th percentile
Published
2018-10-02
Updated
2024-09-17

Proof-of-concept exploits (1)

References

Related