CVE-2016-6742: Critical severity Google Android vulnerability
Published Nov 7, 2016
·Updated
An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30799828.
Affected Software
2 affected components
Google Android<=7.0
Google Android
Remediation
Patch Available
Event History
Nov 7, 2016
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Nov 25, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What devices are exposed to this issue?
Android devices that use the Synaptics touchscreen driver and run a version before 2016-11-05 are affected.
2
What does an attacker need to exploit it?
Exploitation is local and requires user interaction. The issue first requires compromise of a privileged process before a malicious application can execute code in the kernel context.
3
Is a patch available?
Yes. A patch is available; update to the applicable Android security fix level or vendor-provided update addressing the 2016-11-05 cutoff.