First published: Mon Apr 03 2017(Updated: )
An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | <7.0 | |
Google Products | ||
Google Pixel XL |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5346 is classified as an information disclosure vulnerability.
Fixing CVE-2016-5346 involves updating the Google Pixel or Pixel XL device to a secure version of Android beyond 7.0.
CVE-2016-5346 affects Google Pixel and Google Pixel XL devices running Android versions up to 7.0.
No, CVE-2016-5346 requires local access for exploitation by a malicious user.
CVE-2016-5346 can potentially allow a local user to obtain sensitive information from the affected system.