CVE-2018-9537 is an out-of-bounds write vulnerability in the CAacDecoder_DecodeFrame function within Android's media server, affecting Android-9. This critical flaw (CVSS 8.8) allows for potential remote code execution with high impact on confidentiality, integrity, and availability, though user interaction is required for exploitation. While no public exploit code or active exploitation is confirmed, the vulnerability has received some media coverage and community discussion. Its EPSS score is low, suggesting a lower likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.