CVE-2016-6740: Critical severity Google Android vulnerability
An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30143904. References: Qualcomm QC-CR#1056307.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What access or precondition does an attacker need to exploit this issue?
The vulnerability is locally exploitable and requires user interaction. It also first requires compromise of a privileged process before a malicious application can execute code in the kernel context.
What is the potential impact after successful exploitation?
A successful exploit can allow arbitrary code execution in the context of the Android kernel, with resulting high impact to confidentiality, integrity, and availability.
How can this issue be remediated?
A patch is available. The issue affects Android versions before 2016-11-05, so systems should apply the relevant Android security update or vendor-provided patch.