CVE-2016-10472: Critical severity Google Android vulnerability
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, and SDX20, address and size passed to SCM command 'TZINFOGETSECURESTATELEGACYID' from HLOS Kernel were not being checked, so access outside DDR would occur.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10472?
The severity of CVE-2016-10472 is critical with a severity value of 9.8.
Which software is affected by CVE-2016-10472?
CVE-2016-10472 affects Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear devices.
How can I fix CVE-2016-10472?
To fix CVE-2016-10472, make sure to update your Android device to the latest security patch level provided by Google.
Where can I find more information about CVE-2016-10472?
You can find more information about CVE-2016-10472 on the SecurityFocus website and the official Android security bulletin for April 2018.
What is the Common Weakness Enumeration (CWE) for CVE-2016-10472?
The CWE for CVE-2016-10472 is 284.