CVE-2016-6745: Critical severity Google Android vulnerability
Published Nov 7, 2016
·Updated
An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-31252388.
Affected Software
3 affected components
Google Android<=7.1.0
Google Android=7.0
Google Android
Remediation
Patch Available
Event History
Nov 7, 2016
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Nov 25, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What conditions are required for exploitation?
Exploitation requires local access and user interaction, and the issue first requires compromise of a privileged process. A successful attack can then execute arbitrary code in the kernel context.
2
Which systems are affected?
Android devices using the Synaptics touchscreen driver are affected if they were not patched before 2016-11-05.
3
What is the remediation?
Apply the available patch from the Android security update addressing Android ID A-31252388.