CVE-2018-9471 PUBLISHED CVSS 7.800000190734863 HIGH

In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS 0.14% · 33.7th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.14%
33.7th percentile

Affected Products

VendorProductVersions
googleandroid7.0, 8.0, 8.1
GoogleAndroidnyc-mr1-dev, nyc-mr2-dev, 7
googleandroid7.0, 7.1.1, 7.1.2

Timeline

References

Open in Interactive Console →