CVE-2016-6741: Critical severity Google Android vulnerability
An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30559423. References: Qualcomm QC-CR#1060554.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Devices running affected versions of Google Android before 2016-11-05 with the Qualcomm camera driver are in scope. Exploitation is local, so an attacker needs code execution on the device rather than network access.
What does an attacker need to exploit it?
The attacker must get a victim to interact with a malicious local application. The issue is described as first requiring compromise of a privileged process before arbitrary kernel-context code execution can occur.
What is the impact after successful exploitation?
Successful exploitation can allow arbitrary code execution in the kernel context, with high impact to confidentiality, integrity, and availability.
How should affected devices be remediated?
Apply the available Android security patch for this issue. The affected period is Android releases before 2016-11-05.