CVE Published: 19/11/2024 |
CVE Updated: 20/11/2024 |
CVE Year: 2018 Source: google_android |
Vendor: Google |
Product: Android Status : PUBLISHED
CVE-2018-9371 Description
In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with insufficient blacklisting/whitelisting. This could lead to local elevation of privilege, given physical access to the device with no additional execution privileges needed. User interaction is needed for exploitation.