CVE-2016-6720: Infoleak
An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-29422020.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6720?
CVE-2016-6720 is classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2016-6720?
To mitigate CVE-2016-6720, users should update their Android devices to the latest version that is not affected by this vulnerability.
What versions of Android are affected by CVE-2016-6720?
CVE-2016-6720 affects Android versions prior to 4.4.4, 5.0.2, 5.1.1, and 6.0.1, as well as Android 7.0 before November 1, 2016.
Can a malicious app exploit CVE-2016-6720?
Yes, a local malicious application can exploit CVE-2016-6720 to access data outside of its designated permission levels.
Is CVE-2016-6720 a critical vulnerability?
CVE-2016-6720 is not classified as critical, but it poses a risk of information disclosure that should be addressed promptly.