CVE-2018-9560 is an out-of-bounds write vulnerability in the HID_DevAddRecord function of hidd_api.cc, affecting Android 9. This flaw allows for local escalation of privilege within the Bluetooth service, requiring only user execution privileges and no user interaction. With a CVSS score of 7.8 (High), it presents a significant risk of high impact to confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are available, and there is minimal community discussion or media coverage, its potential for privilege escalation warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.