CVE-2016-2417 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 5.3% (pctl 92)
Patch early
A public exploit exists.
Description
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.32% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2016-04-18 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| android |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Google Android - IOMX 'getConfig'/'getParameter' Information Disclosure | 2016-04-11 |
References
- http://source.android.com/security/bulletin/2016-04-02.html
- https://android.googlesource.com/platform/frameworks/av/+/1171e7c047bf79e7c93342bb6a812c9edd86aa84
- https://www.exploit-db.com/exploits/39685/
- http://source.android.com/security/bulletin/2016-04-02.html
- https://android.googlesource.com/platform/frameworks/av/+/1171e7c047bf79e7c93342bb6a812c9edd86aa84
- https://www.exploit-db.com/exploits/39685/
→ the Explorer · watch your stack · NVD