CVE-2016-7991: High severity android vulnerability
On Samsung Galaxy S4 through S7 devices, the "omacp" app ignores security information embedded in the OMACP messages resulting in remote unsolicited WAP Push SMS messages being accepted, parsed, and handled by the device, leading to unauthorized configuration changes, a subset of SVE-2016-6542.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7991?
CVE-2016-7991 is classified as a high-severity vulnerability due to its potential for unauthorized configuration changes on affected devices.
How do I fix CVE-2016-7991?
Fixing CVE-2016-7991 involves updating the affected Samsung Galaxy devices to the latest security patch provided by Samsung.
What devices are affected by CVE-2016-7991?
CVE-2016-7991 affects Samsung Galaxy S4, S5, S6, S7, and various versions of Android from 4.2.2 to 6.0.1.
What is the impact of CVE-2016-7991?
The impact of CVE-2016-7991 includes the acceptance and handling of malicious WAP Push SMS messages leading to unauthorized changes.
Was CVE-2016-7991 disclosed publicly?
Yes, CVE-2016-7991 was publicly disclosed in August 2016 as part of Samsung's security updates.