Possible Out of Bounds Read Leads to Local Information Disclosure Over Bluetooth
CVE-2018-9486

6.5MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
20 November 2024

What is CVE-2018-9486?

A vulnerability exists in the Bluetooth implementation of Android devices that allows for potential local information disclosure. This issue arises from a missing bounds check within the hidh_l2cif_data_ind function of the hidh_conn.cc module. As a result, an attacker could exploit this vulnerability through Bluetooth communication, allowing them to read sensitive information without requiring any user interaction or special execution privileges. The affected Android versions range from 4.4 to 9.0, making a significant number of devices vulnerable to this type of attack, which could lead to unauthorized information access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Android 7

Android 8

Android 8.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.