CVE-2016-8464: High severity android vulnerability
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-29000183. References: B-RB#106314.
Affected Software
Event History
Frequently Asked Questions
Which Android systems are affected?
Android devices using Kernel-3.10 or Kernel-3.18 with the affected Broadcom Wi-Fi driver are in scope. The issue is associated with Android ID A-29000183.
What would an attacker need to exploit this issue?
Exploitation is local and requires user interaction, and the attacker starts from a malicious local application. The issue also first requires compromise of a privileged process, which current platform configurations mitigate.
What is the impact of successful exploitation?
Successful exploitation could allow arbitrary code execution in the kernel context, with resulting impact to confidentiality, integrity, and availability.