CVE-2016-10428: Infoleak
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, HMAC verification in counter file uses an insecure memcmp which may assist a timing attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10428?
CVE-2016-10428 has a high severity rating due to its potential to enable timing attacks via insecure HMAC verification.
How do I fix CVE-2016-10428?
To fix CVE-2016-10428, ensure that your device is updated with the latest security patch provided by Qualcomm.
What devices are affected by CVE-2016-10428?
CVE-2016-10428 affects devices running on Qualcomm Snapdragon SD 425, SD 430, SD 450, SD 625, SD 650/652, SD 820, and SD 820A before the 2018-04-05 security patch.
What vulnerabilities arise from CVE-2016-10428?
CVE-2016-10428 can lead to timing attacks that compromise HMAC verification in counter files.
Is CVE-2016-10428 part of the Android security updates?
Yes, CVE-2016-10428 is addressed in the Android security updates released on or after 2018-04-05.