Potential Permissions Bypass in BluetoothPermissionActivity
CVE-2018-9432

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
19 November 2024

What is CVE-2018-9432?

A vulnerability exists within BluetoothPermissionActivity.java related to the createPhonebookDialogView and createMapDialogView functions, which may allow attackers to bypass the permissions settings for accessing user contacts. This flaw can lead to unauthorized access, as it hides the user's ability to disable contact access, potentially leading to local privilege escalation without requiring additional execution privileges. Exploitation necessitates user interaction, making it essential for users to be cautious when granting permissions related to Bluetooth services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Android 6

Android 6.0.1

Android 7

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.