KASLR Bypass Vulnerability in Android Devices by Google
CVE-2018-9384

4.4MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
17 January 2025

What is CVE-2018-9384?

This vulnerability allows for a potential bypass of Kernel Address Space Layout Randomization (KASLR) in certain Android versions. Due to an unusual root cause, attackers may exploit this vulnerability to disclose sensitive information locally. The exploitation does not require user interaction, and the vulnerability could lead to unauthorized access to system resources, making it critical for users to update their devices to the latest security patches provided by Google.

Affected Version(s)

Android Android Kernel

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.