Vulnerability Description
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | 6.0 | |
| Lg | G5 | - |
| Lg | G6 | - |
| Lg | G6\+ | - |
| Lg | Q6 | - |
| Lg | Q8 | - |
| Lg | V10 | - |
| Lg | V20 | - |
| Lg | V30 | - |
| Lg | V30\+ | - |
| Lg | V30S Thinq | - |
| Lg | X Cam | - |
| Lg | X300 | - |
| Lg | X400 | - |
| Lg | X500 | - |
Related Weaknesses (CWE)
References
- https://lgsecurity.lge.com/security_updates.htmlThird Party Advisory
- https://www.kryptowire.com/portal/android-firmware-defcon-2018/Third Party Advisory
- https://lgsecurity.lge.com/security_updates.htmlThird Party Advisory
- https://www.kryptowire.com/portal/android-firmware-defcon-2018/Third Party Advisory
FAQ
What is CVE-2018-15482?
CVE-2018-15482 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006.
How severe is CVE-2018-15482?
CVE-2018-15482 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-15482?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Lg G5, Lg G6, Lg G6\+, Lg Q6.