logo

CVE-2018-9539: Use-after-free vulnerability in privileged Android service

ID: 552196cf-bc3c-5ea1-9c8c-3e0b9948ead0

STIX ID: report--552196cf-bc3c-5ea1-9c8c-3e0b9948ead0

Feed Name: Zimperium Blog

Threat Score
30/100

Date Published: 2018-11-09

Date Updated: 2026-05-01

...
...

This report details a use-after-free vulnerability (CVE-2018-9539) in Android's MediaCasService ClearKey plugin (libclearkeycasplugin.so). A race condition allows a Descrambler to invoke decrypt on a session object whose reference count has dropped to zero, leading to use-after-free; a provided PoC triggers a crash on Android 9 due to destroyed mutex behavior. Google patched the issue in the November 2018 security update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.