CVE-2016-8454: High severity android vulnerability
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32174590. References: B-RB#107142.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Exposure is limited to Android devices using the affected Broadcom Wi-Fi driver on Kernel-3.10 or Kernel-3.18. The vulnerable component executes in the kernel context, so successful exploitation can result in arbitrary kernel code execution.
What must an attacker achieve before exploiting this vulnerability?
An attacker needs local execution through a malicious application and user interaction, as reflected by the local attack vector and required user interaction. The issue is also described as first requiring compromise of a privileged process.
How can I determine whether a device is affected?
The provided information does not state whether the affected Broadcom Wi-Fi driver is enabled or present in default Android device configurations. Determine exposure by checking whether the device uses that driver and runs Kernel-3.10 or Kernel-3.18.