CVE-2018-9377

In getIntentForIntentSender of ActivityManagerService.java, there is a possible way to access user metadata due to a pending intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*

History

17 Jun 2026, 02:06

Type Values Removed Values Added
Summary (es) En BnAudioPolicyService::onTransact de IAudioPolicyService.cpp, existe una posible divulgación de información debido a datos no inicializados. Esto podría generar una divulgación de información local sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación. (es) En getIntentForIntentSender de ActivityManagerService.java, existe una posible forma de acceder a metadatos de usuario debido a un intent pendiente. Esto podría llevar a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. La interacción del usuario no es necesaria para la explotación.

17 Jan 2025, 23:15

Type Values Removed Values Added
Summary (en) In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. (en) In getIntentForIntentSender of ActivityManagerService.java, there is a possible way to access user metadata due to a pending intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

18 Dec 2024, 20:25

Type Values Removed Values Added
First Time Google
Google android
CPE cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 6.2
v2 : unknown
v3 : 5.5
References () https://source.android.com/docs/security/bulletin/pixel/2018-06-01 - () https://source.android.com/docs/security/bulletin/pixel/2018-06-01 - Vendor Advisory

29 Nov 2024, 22:15

Type Values Removed Values Added
CWE CWE-908
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2

28 Nov 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-28 01:15

Updated : 2026-06-17 02:06


NVD link : CVE-2018-9377

Mitre link : CVE-2018-9377

CVE.ORG link : CVE-2018-9377


JSON object : View

Products Affected

google

  • android
CWE
CWE-908

Use of Uninitialized Resource