CVE-2018-9474 Information

Description

In writeToParcel of MediaPlayer.java there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Reference

https://source.android.com/security/bulletin/2018-09-01

Share on: