CVE-2016-6739: Critical severity Google Android vulnerability
An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30074605. References: Qualcomm QC-CR#1049826.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What level of access does an attacker need before exploiting this issue?
The issue is locally exploitable without declared privileges, but successful exploitation first requires compromise of a privileged process. User interaction is also required according to the supplied CVSS vector.
What is the potential impact after successful exploitation?
A local malicious application could execute arbitrary code in the kernel context. This can affect confidentiality, integrity, and availability at a high level.
What remediation is available?
A patch is available. The issue affects Android versions before 2016-11-05, so organizations should apply the applicable Android security update.