CVE-2018-9345

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Nov 19, 2024
Updated: Nov 22, 2024
CWE ID 908

Summary

CVE-2018-9345 is a vulnerability affecting the AudioPolicyService component in BnAudioPolicyService of Google's Android OS. The issue lies within the function "onTransact" in AudioPolicyService.cpp, where uninitialized data may be disclosed, resulting in local information exposure. No additional execution privileges are required for an attacker to exploit this vulnerability, making it a potential threat even without user interaction.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share