CVE-2017-18685: Google Android

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. The InputMethod application can cause a system crash via a malformed serializable object in an Intent. The Samsung ID is SVE-2016-7123 (February 2017).

Affected products

  • Google Android: version 4.4 only; version 5.0 only; version 5.1 only; version 6.0 only

Published 2020-04-07. Last modified 2026-06-17.