VDB
CVE-2018-9374
CVE-2018-9374
PUBLISHED
CVSS 7.800000190734863 HIGH
In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
EPSS 0.08% · 0.3th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.08%
0.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| pixel | 0 | |
| Android | 7.1.2, 6, 6.0.1 | |
| android | 6.0.1, 7.0, 7.1.1 | |
| android | 0 |
Timeline
- Nov 27, 2024 CVE Published
- Nov 28, 2024 EPSS Score
- Dec 16, 2024 EPSS Score
- Dec 18, 2024 CVE Updated
- Jan 2, 2025 EPSS Score
- Jan 20, 2025 EPSS Score
- Feb 6, 2025 EPSS Score
- Feb 23, 2025 EPSS Score
- Mar 12, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
- Apr 16, 2025 EPSS Score
- May 3, 2025 EPSS Score