CVE-2015-6647: Critical severity android vulnerability
Published Jan 4, 2016
·Updated
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24441554.
Affected Software
7 affected components
Google Android=5.0
Google Android=5.0.1
Google Android=5.0.2
Google Android=5.1.0
Google Android=5.1.1
Google Android=6.0
Google Android
Event History
Jan 4, 2016
CVE Published
via Android·12:00 AM
Jan 6, 2016
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6647?
CVE-2015-6647 has been classified as a high-severity vulnerability due to its potential to allow privilege escalation.
2
How do I fix CVE-2015-6647?
To fix CVE-2015-6647, ensure your Android device is updated to version 5.1.1 LMY49F or later.
3
What versions of Android are affected by CVE-2015-6647?
CVE-2015-6647 affects Android versions 5.0 through 5.1.1 and version 6.0 before January 1, 2016.
4
What type of attack does CVE-2015-6647 enable?
CVE-2015-6647 enables attackers to gain elevated privileges through a crafted application utilizing QSEECOM access.
5
Is the QSEE TrustZone application in Android vulnerable due to CVE-2015-6647?
Yes, the QSEE TrustZone application in specific versions of Android is vulnerable due to CVE-2015-6647.