CVE-2016-6737: Critical severity Google Android vulnerability
An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30928456.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Android devices with the affected kernel ION subsystem that have not received the Android security update dated 2016-11-05 are exposed.
What does an attacker need to exploit it?
Exploitation requires a malicious application to run locally on the device. The CVSS vector indicates no privileges are required, but user interaction is required.
What is the potential impact of successful exploitation?
A local malicious application could execute arbitrary code in the kernel context, resulting in a permanent device compromise. Recovery may require reflashing the operating system.
What should be done to remediate the issue?
Apply the available Android patch/security update addressing this issue. The Android security bulletin dated 2016-11-05 is identified as the relevant update.