First published: Mon Apr 18 2016(Updated: )
media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize certain metadata buffer pointers, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26324358.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =6.0 | |
Google Android | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2418 is classified as a high severity vulnerability due to its potential to expose sensitive information.
To mitigate CVE-2016-2418, update your Android device to the latest available version that addresses this vulnerability.
CVE-2016-2418 affects Android versions 6.0 and 6.0.1.
CVE-2016-2418 exploits the lack of initialization of certain metadata buffer pointers in mediaserver.
CVE-2016-2418 allows attackers to obtain sensitive information, posing a risk for potential remote exploitation.