VYPR
Medium severity6.4NVD Advisory· Published Nov 19, 2024· Updated Jun 17, 2026

CVE-2018-9371

CVE-2018-9371

Description

In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with insufficient blacklisting/whitelisting. This could lead to local elevation of privilege, given physical access to the device with no additional execution privileges needed. User interaction is needed for exploitation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Google/Android2 versions
    cpe:2.3:o:google:android:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
    • (no CPE)range: SoCVersion

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.