CVE-2016-8412: High severity android vulnerability
An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31225246. References: QC-CR#1071891.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed?
Exposure is limited to Android devices using the affected Qualcomm camera kernel code in Kernel-3.10 or Kernel-3.18. The issue enables code execution in kernel context, affecting confidentiality, integrity, and availability.
What does an attacker need to exploit this issue?
An attacker needs to run a malicious application locally and must first compromise a privileged process. The CVSS vector also indicates high attack complexity and required user interaction.
How can I determine whether a device has been remediated?
Check whether the device uses Kernel-3.10 or Kernel-3.18 and whether its Android security updates include the fix for Android ID A-31225246 or Qualcomm reference QC-CR#1071891. The cited Android security bulletin is dated 2017-01-01.