CVE-2014-9783: Critical severity Google Android vulnerability
Published Jul 11, 2016
·Updated
drivers/media/platform/msm/camerav2/sensor/cci/msmcci.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices does not validate certain values, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28441831 and Qualcomm internal bug CR511382.
Affected Software
1 affected component
Google Android<=6.0.1
Event History
Jul 11, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
Which devices are identified as affected?
The issue is identified on Nexus 7 (2013) devices running Android versions before 2016-07-05.
2
What does an attacker need to exploit this issue?
An attacker needs to get a crafted application onto the device. The CVSS vector indicates no privileges are required beforehand, but user interaction is required.
3
What is the potential impact of successful exploitation?
A successful attacker can gain elevated privileges, with high impact to confidentiality, integrity, and availability according to the supplied CVSS vector.