First published: Tue Jan 03 2017(Updated: )
An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31528889. References: MT-ALPS02961395.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | <=7.1.0 | |
Android | ||
<=7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8470 is rated as Moderate due to its requirement for a local malicious application to compromise a privileged process.
To mitigate CVE-2016-8470, update to the latest version of Android that addresses this vulnerability.
CVE-2016-8470 can be exploited by a local malicious application to access data outside its permission levels.
CVE-2016-8470 affects Android versions up to and including 7.1.0.
Only a local malicious application with access to a privileged process can exploit the CVE-2016-8470 vulnerability.