CVE-2018-9411: New critical vulnerability in multiple high-privileged Android services
ID: 3b65069f-02da-5897-b184-c8b806da8508
STIX ID: report--3b65069f-02da-5897-b184-c8b806da8508
Feed Name: Zimperium Blog
Zimperium zLabs disclosed `CVE-2018-9411`, a HIDL hidl_memory size-truncation vulnerability that lets 32-bit Android HAL services treat a truncated 64-bit size as much larger than the actual mapped region, enabling out-of-bounds read/write. The blog gives a full technical analysis and a proof-of-concept exploit targeting android.hardware.cas (MediaCasService) to hijack a blocked thread, execute a ROP chain, and call a TEE ioctl (demonstrating local privilege escalation); Google issued patches in the July and September 2018 security updates and the PoC code was published for defensive/educational use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
