CVE-2018-9531 is an out-of-bounds write vulnerability in Android's AudioSpecificConfig_Parse function, affecting Android 9. This flaw, rated High severity (CVSS 7.8), could enable remote code execution without additional privileges, though user interaction is required for exploitation. While no public exploits or Metasploit modules exist, the vulnerability has garnered some community discussion and media coverage, indicating awareness. Despite its potential impact, it is not currently listed on CISA's KEV catalog and its EPSS score suggests a low likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.