CVE-2016-2567: Input Validation
secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by the http://should-have-been-filtered.example.com/?http://google.com URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2567?
The severity of CVE-2016-2567 is classified as medium, indicating a potential impact on user devices.
How do I fix CVE-2016-2567?
To fix CVE-2016-2567, update your Samsung Galaxy S6 or Galaxy Note 3 device to the latest firmware version provided by Samsung.
Which devices are affected by CVE-2016-2567?
CVE-2016-2567 affects the Samsung Galaxy S6 with firmware version G920FXXU2COH2 and the Galaxy Note 3 with firmware version N9005XXUGBOB6.
What is the main vulnerability in CVE-2016-2567?
The main vulnerability in CVE-2016-2567 is the ability for attackers to bypass URL filtering by manipulating the query string with exceptional URLs.
Can CVE-2016-2567 allow unauthorized access to my device?
Yes, CVE-2016-2567 could allow unauthorized access to restricted content by bypassing URL filtering mechanisms.