CVE-2016-8466: High severity android vulnerability
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31822524. References: B-RB#105268.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed?
The affected product information identifies Android systems using Kernel-3.10 or Kernel-3.18 with the Broadcom Wi-Fi driver. The issue is local, so it is not described as remotely exploitable over the network.
What does an attacker need to exploit this issue?
An attacker needs a local malicious application and user interaction. The vulnerability also first requires compromise of a privileged process, according to the advisory.
Does the platform configuration provide any mitigation?
Current platform configurations mitigate the issue, but the supplied data does not identify the specific configuration controls. The vulnerability can allow arbitrary code execution in kernel context if exploited.
How can I determine whether a device may be affected?
Review whether the affected Android device uses the Broadcom Wi-Fi driver on Kernel-3.10 or Kernel-3.18, and correlate the issue with Android ID A-31822524. The provided information does not include a separate detection method or indicator of compromise.