CVE-2018-9539: Use-after-free vulnerability in privileged Android service
ID: 552196cf-bc3c-5ea1-9c8c-3e0b9948ead0
STIX ID: report--552196cf-bc3c-5ea1-9c8c-3e0b9948ead0
Feed Name: Zimperium Blog
Threat Score
This report details a use-after-free vulnerability (CVE-2018-9539) in Android's MediaCasService ClearKey plugin (libclearkeycasplugin.so). A race condition allows a Descrambler to invoke decrypt on a session object whose reference count has dropped to zero, leading to use-after-free; a provided PoC triggers a crash on Android 9 due to destroyed mutex behavior. Google patched the issue in the November 2018 security update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
