CVE-2016-6729: Critical severity Google Android vulnerability
An elevation of privilege vulnerability in the Qualcomm bootloader in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30977990. References: Qualcomm QC-CR#977684.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6729?
CVE-2016-6729 is rated as Critical due to the potential for local permanent device compromise.
How do I fix CVE-2016-6729?
To fix CVE-2016-6729, update your affected Android device to a version that addresses this vulnerability, specifically versions after 2016-11-05.
Which versions of Android are affected by CVE-2016-6729?
CVE-2016-6729 affects Android versions up to and including 7.1.0.
What type of vulnerability is CVE-2016-6729?
CVE-2016-6729 is an elevation of privilege vulnerability in the Qualcomm bootloader.
Can a malicious application exploit CVE-2016-6729?
Yes, a local malicious application can exploit CVE-2016-6729 to execute arbitrary code within the context of the kernel.