In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to local escalation of privilege due to hiding and bypassing the user's ability to disable access to contacts, with no additional execution privileges needed. User interaction is needed for exploitation.
                
            References
                    | Link | Resource | 
|---|---|
| https://source.android.com/security/bulletin/2018-07-01 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    22 Nov 2024, 21:11
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:7.1.1:*:*:*:*:*:*:* cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:* cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:7.1.2:*:*:*:*:*:*:* cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:* | |
| References | () https://source.android.com/security/bulletin/2018-07-01 - Vendor Advisory | |
| CWE | NVD-CWE-noinfo | |
| First Time | Google Google android | 
20 Nov 2024, 16:35
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-276 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.8 | 
| Summary | 
 | 
19 Nov 2024, 22:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-11-19 22:15
Updated : 2024-11-22 21:11
NVD link : CVE-2018-9432
Mitre link : CVE-2018-9432
CVE.ORG link : CVE-2018-9432
JSON object : View
Products Affected
                - android
CWE
                