CVE-2016-8452: High severity android vulnerability
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32506396. References: QC-CR#1050323.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
Exploitation is local and requires user interaction. The issue is described as first requiring compromise of a privileged process before a malicious application can execute code in the kernel context.
Which Android kernel versions are identified as affected?
The listed affected versions are Kernel-3.10 and Kernel-3.18 for Android.
What is the likely impact after successful exploitation?
A successful exploit can allow arbitrary code execution in the kernel context, with resulting confidentiality, integrity, and availability impact rated High in the provided CVSS vector.