In run of InstallPackageTask.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, it is possible that package verification is turned off and remains off due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-116754444.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published: 2019-02-12T00:00:00Z

Updated: 2024-09-16T16:58:02.607Z

Reserved: 2018-04-05T00:00:00

Link: CVE-2018-9586

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-02-11T23:29:00.420

Modified: 2019-02-12T18:44:13.033

Link: CVE-2018-9586

cve-icon Redhat

No data.