Information Disclosure Vulnerability in Android AOSP BnAudioPolicyService
CVE-2018-9378

6.2MEDIUM

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
28 January 2025

Summary

The BnAudioPolicyService component in Android AOSP contains a vulnerability that may allow local information disclosure due to uninitialized data. This flaw can potentially expose sensitive information without requiring elevated privileges or user interaction to exploit. Systems running affected versions of Android AOSP prior to the June 2018 security patch level are particularly at risk.

Affected Version(s)

Android Android Kernel

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.