First published: Mon Apr 18 2016(Updated: )
server/content/ContentService.java in the Framework component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a GET_ACCOUNTS permission, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 26094635.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =4.0 | |
Google Android | =4.0.1 | |
Google Android | =4.0.2 | |
Google Android | =4.0.3 | |
Google Android | =4.0.4 | |
Google Android | =4.1 | |
Google Android | =4.1.2 | |
Google Android | =4.2 | |
Google Android | =4.2.1 | |
Google Android | =4.2.2 | |
Google Android | =4.3 | |
Google Android | =4.3.1 | |
Google Android | =4.4 | |
Google Android | =4.4.1 | |
Google Android | =4.4.2 | |
Google Android | =4.4.3 | |
Google Android | =5.0 | |
Google Android | =5.0.1 | |
Google Android | =5.1 | |
Google Android | =5.1.0 | |
Google Android | =6.0 | |
Google Android | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2426 is categorized as a high severity vulnerability due to the potential for unauthorized access to sensitive user information.
To fix CVE-2016-2426, update your Android device to a version released after April 1, 2016, or apply the corresponding security patch.
CVE-2016-2426 affects Android versions 4.0 through 6.0.1 prior to the security updates released in April 2016.
CVE-2016-2426 allows attackers to potentially access sensitive user data, including account information, through malicious applications.
It is not safe to use devices running vulnerable versions of Android related to CVE-2016-2426, and users should update to a patched version immediately.