CVE-2018-9582 describes a local escalation of privilege vulnerability affecting Android versions 8.0, 8.1, and 9, specifically within the package installer. This flaw, stemming from a confused deputy scenario, allows a bypass of the unknown source warning. With a CVSS score of 7.8 (High), it requires no user interaction or additional execution privileges for exploitation, leading to high impacts on confidentiality, integrity, and availability. While no public exploit code or Metasploit modules are available, the vulnerability has garnered some community discussion and media coverage, though it is not currently listed on the CISA KEV catalog as being actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.