Possible Information Leak in Binder due to Uninitialized Data
CVE-2018-9421
Currently unrated 🤨
Summary
In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Version(s)
Android = 6
Android = 6.0.1
Android = 7
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database