First published: Mon Jan 04 2016(Updated: )
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24441554.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =5.0 | |
Android | =5.0.1 | |
Android | =5.0.2 | |
Android | =5.1.0 | |
Android | =5.1.1 | |
Android | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6647 has been classified as a high-severity vulnerability due to its potential to allow privilege escalation.
To fix CVE-2015-6647, ensure your Android device is updated to version 5.1.1 LMY49F or later.
CVE-2015-6647 affects Android versions 5.0 through 5.1.1 and version 6.0 before January 1, 2016.
CVE-2015-6647 enables attackers to gain elevated privileges through a crafted application utilizing QSEECOM access.
Yes, the QSEE TrustZone application in specific versions of Android is vulnerable due to CVE-2015-6647.