peter bassill · operator
$ cve CVE-2016-6754 JSON

CVE-2016-6754 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 4.6% (pctl 91)

Patch early

A public exploit exists.

Description

A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is rated as High due to the possibility of remote code execution in an unprivileged process. Android ID: A-31217937.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS4.59% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-74
On CISA KEVno
Public exploityes
Published2016-11-25
Last modified2026-06-17

Affected (1)

VendorProduct
googleandroid

Public exploits

SourceTitleDate
exploit-dbGoogle Android - 'BadKernel' Remote Code Execution2016-11-28

References

→ the Explorer  ·  watch your stack  ·  NVD