CVE-2018-9556 is a critical out-of-bounds write vulnerability affecting Android 9, stemming from an integer overflow in the ParsePayloadHeader function. This flaw allows for remote escalation of privilege without requiring user interaction or additional execution privileges. With a CVSS score of 9.8, it poses a significant risk, enabling complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been identified, and community discussion is minimal, its high severity warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.